bexio

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match its stated Bexio-integration purpose, and installation comes from an official registry rather than an ad-hoc download. The main concern is data-flow integrity and trust expansion: all Bexio access, authentication, and action execution are routed through Membrane as a third-party intermediary CLI/service, including dynamically generated actions, which is broader trust than a direct Bexio integration. This is not confirmed malware, but it carries moderate security risk and credential/data exposure concerns inherent to the proxy architecture.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 08:43 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbexio%2F@60ce3d7395f699b70f36aea761bd6ca9e7d4fe0e
Security Audit — socket — bexio