constant-contact

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent for a Membrane-hosted Constant Contact integration, and the CLI comes from an official npm package matching the publisher. However, it routes authentication, credential storage, and API activity through Membrane as a third-party intermediary instead of direct Constant Contact APIs, and it uses an unpinned global CLI install. This is not confirmed malware, but it carries medium security/privacy risk due to the added trust boundary and server-side credential handling.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 07:29 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fconstant-contact%2F@9c98655f24963acea9297645735243a62343ecd9