confluence

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities match its stated Confluence-integration purpose, and the CLI comes from an official npm package tied to the same product ecosystem. However, authentication and all Confluence operations are mediated through Membrane, so credentials and document data flow through a third-party platform instead of directly to Atlassian. This is coherent for the product but increases trust and data-handling risk, especially with an unpinned global CLI install and write/delete capabilities.

Confidence: 85%Severity: 53%
Audit Metadata
Analyzed At
Apr 28, 2026, 12:55 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fconfluence%2F@3ea8218352c9feee0f4c202d4f10d9d0169ac77d