cisco-webex

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly aligned with Webex integration, and the CLI comes from an official registry, but the actual data flow is through Membrane’s managed proxy and credential store rather than directly to Cisco Webex. That third-party credential forwarding and remote action capability are proportionate to the product’s model but still create medium security risk, especially with an unpinned CLI install and broad ability to modify external Webex resources.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcisco-webex%2F@1b00ee287d56e2ded2313a39ca9f3c1e747360fa