ashby

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent and uses an official same-org npm CLI, so it does not look malicious. However, it routes Ashby authentication and recruiting data through Membrane as an intermediary and enables write actions against an ATS, creating moderate trust and data-governance risk beyond a direct first-party API integration.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 11:09 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fashby%2F@ca7c6857d38f4e08a551159eddbb1e949a76b60a
Security Audit — socket — ashby