clari

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and commands are internally consistent, and the install source appears legitimate, but all Clari auth and API traffic is routed through Membrane rather than directly to Clari. This third-party intermediary model is proportionate to the product but introduces medium security risk from credential/data handling and unpinned CLI installation.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:04 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fclari%2F@55bc2466cf2ca603b42a5de608546f91ce720352
Security Audit — socket — clari