applicantstack

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities are broadly aligned, and the CLI comes from an official npm package rather than an unverifiable binary. However, all ApplicantStack access is mediated through Membrane's hosted platform instead of direct official API calls, creating a third-party data and credential trust boundary; combined with mutable `@latest` installs, this makes the skill moderately risky rather than benign.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 09:43 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fapplicantstack%2F@3cab5bc2df9e714d012b96c6a94c5514d6b5590a
Security Audit — socket — applicantstack