bloomreach

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, and the CLI source appears legitimate, but the actual integration path routes BloomReach authentication and API traffic through Membrane’s intermediary platform rather than directly to official BloomReach APIs. That creates medium risk from third-party credential and data handling, though there is no clear evidence of malware or covert exfiltration.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:20 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbloomreach%2F@9fdf44aa16c2953b765cffac36deb3879de20146
Security Audit — socket — bloomreach