bluecart-api

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is not overtly malicious and uses an apparently official Membrane CLI from npm, but it routes BlueCart access, authentication, and requests through Membrane as a third-party intermediary instead of direct BlueCart APIs. Combined with stale docs and Walmart copy/paste inconsistencies, the skill is internally inconsistent enough to warrant caution.

Confidence: 86%Severity: 59%
Audit Metadata
Analyzed At
Apr 30, 2026, 07:06 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbluecart-api%2F@5def8a9f55f463518e42c924bda20a6911966f39
Security Audit — socket — bluecart-api