cybersource

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities mostly align, and the installer appears to be an official same-org npm package rather than an unverifiable payload. However, the integration routes CyberSource access through Membrane-managed auth and proxy services instead of direct official CyberSource API use, creating a meaningful third-party trust and data-flow risk for payment-related operations.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
May 1, 2026, 12:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcybersource%2F@9a80e2002ca3d151fcc9c262f806900bf71e033c
Security Audit — socket — cybersource