baremetrics

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, and the CLI install path is from an official registry, but the integration routes Baremetrics access through Membrane instead of the official Baremetrics API and requires trusting a third-party account, CLI, and credential-management layer. This is a coherent SaaS-integration design, not confirmed malware, but it creates medium security risk from intermediary data/credential handling and unpinned CLI installation.

Confidence: 84%Severity: 59%
Audit Metadata
Analyzed At
Apr 29, 2026, 11:09 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbaremetrics%2F@57a9c2b77f14bb1e261f782d12be2c457c2ce72f