clickhelp

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a Membrane-based ClickHelp integration, and its CLI install path is same-org and registry-based rather than a stealth payload. However, it routes ClickHelp authentication and data through Membrane as an intermediary, widening the trust boundary and enabling significant write actions; this is not clearly malicious, but it is a medium-risk third-party gateway pattern.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
May 2, 2026, 10:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fclickhelp%2F@d98d609d3211bdc814034633c10f215d68a9901d
Security Audit — socket — clickhelp