apto-payments

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a Membrane-mediated Apto integration, but it routes authentication and API traffic through Membrane rather than directly to Apto. The install source is relatively trustworthy (official npm package), so this is not strong evidence of malware; the main risk is third-party credential/data mediation plus mutable `@latest` CLI execution.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fapto-payments%2F@c84a7d23d4a1a0bac2ca29657567ddb8b275d513
Security Audit — socket — apto-payments