contractbook

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities broadly align, and the CLI comes from an official registry path tied to the stated vendor, so this is not outright malicious. However, it routes Contractbook access and authentication through Membrane as an intermediary service, expanding data exposure beyond the official API path, and uses mutable `@latest` installs. Risk is mainly third-party data/credential mediation plus moderate supply-chain hygiene concerns, not confirmed malware.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 01:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcontractbook%2F@560aa028dd9550f855c9498b3371bc194e4600b2
Security Audit — socket — contractbook