currencycloud
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is broadly coherent with its stated purpose, and the CLI comes from an official registry source tied to the publisher. However, it routes authentication and Currencycloud operations through Membrane as an intermediary, and it enables potentially sensitive financial workflow actions without explicit per-action approval guidance. This is not confirmed malware, but it carries medium security risk due to third-party credential brokering, intermediary data flows, and unpinned CLI installation.
Confidence: 84%Severity: 60%
Audit Metadata