cherwell-itsm

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent as a Cherwell integration guide, and its install source appears legitimate, but it routes authentication and Cherwell operations through Membrane rather than direct official Cherwell APIs. That intermediary design is disclosed and plausibly intended, so this is not malware, but it creates medium security and data-flow risk.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 08:40 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcherwell-itsm%2F@142ef420840b6e8c0085d961d274fc41595357f6
Security Audit — socket — cherwell-itsm