braintree

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The overall behavior is coherent for a Braintree integration skill, and the CLI install comes from the official npm registry under Membrane's scope, so this is not strong evidence of malware. However, the skill routes all Braintree interaction and credential handling through Membrane rather than Braintree's official API, requiring users to trust a third-party intermediary with payment-platform access and server-side credential storage. That data-flow indirection and dynamic remote action creation make the skill medium risk even though its stated purpose matches its capabilities.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 05:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbraintree%2F@1815d7283b9a0b1a385cf5704eb5d21e744d3858
Security Audit — socket — braintree