bigcommerce

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities match its stated BigCommerce integration purpose, and the CLI comes from an official npm package tied to the same publisher. However, the skill routes authentication and API activity through Membrane rather than directly to BigCommerce, so credentials and store data are entrusted to a third-party intermediary. This is coherent with the skill’s design, so it is not malicious, but it carries medium security risk due to credential/data forwarding and mutable CLI installation.

Confidence: 86%Severity: 53%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbigcommerce%2F@5f07f680bfd92d86e4a196b7499096f447c90950