currencycloud

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent with its stated purpose, and the CLI comes from an official registry source tied to the publisher. However, it routes authentication and Currencycloud operations through Membrane as an intermediary, and it enables potentially sensitive financial workflow actions without explicit per-action approval guidance. This is not confirmed malware, but it carries medium security risk due to third-party credential brokering, intermediary data flows, and unpinned CLI installation.

Confidence: 84%Severity: 60%
Audit Metadata
Analyzed At
Apr 30, 2026, 11:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcurrencycloud%2F@bc3466a1e7c2d2b2216f35c36c308aea5931ae66
Security Audit — socket — currencycloud