bombora

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s behavior mostly matches its stated Bombora-integration purpose, and the install path is a normal npm CLI workflow. The main risk is architectural: all auth and API traffic are routed through Membrane rather than directly to Bombora, so credentials and data handling depend on a third-party intermediary; combined with unpinned CLI execution, this raises medium security risk but does not by itself indicate malware.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:29 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbombora%2F@aa3e5993eb000d950fc7c5c377c5267832f34384
Security Audit — socket — bombora