ashby
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is internally coherent and uses an official same-org npm CLI, so it does not look malicious. However, it routes Ashby authentication and recruiting data through Membrane as an intermediary and enables write actions against an ATS, creating moderate trust and data-governance risk beyond a direct first-party API integration.
Confidence: 86%Severity: 58%
Audit Metadata