basecamp

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's Basecamp management purpose matches its capabilities, and the CLI install path is from a legitimate registry, so this is not outright malicious. However, the integration is materially mediated by Membrane rather than Basecamp's first-party path: authentication, credential refresh, and Basecamp data/actions flow through a third-party service and account, which raises trust and data-flow concerns. Combined with an unpinned global CLI install and dynamic action creation, the skill presents medium risk despite coherent stated purpose.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
Apr 30, 2026, 01:43 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbasecamp%2F@46e2d24397c876576f38764b642752dc0a1acb64