callfire

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated CallFire integration purpose, and the CLI comes from an official npm package rather than an unverifiable binary. The main concern is data-flow integrity: CallFire access is mediated through Membrane, so credentials and data are entrusted to a third-party platform instead of going directly to CallFire’s official API. Combined with unpinned global CLI install and real-world messaging actions, this makes the skill medium risk rather than benign.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:52 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcallfire%2F@8e1f1453aacf944fa89ba368d867797eed8e750a
Security Audit — socket — callfire