degreed

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent as a Membrane-based Degreed connector, and its install path is from an official npm package rather than an unknown binary. However, it materially reroutes Degreed authentication and data through Membrane's intermediary platform and requires a separate Membrane account, which is broader trust than a direct Degreed skill implies. Main risk is third-party credential/data routing plus unpinned CLI execution, not confirmed malware.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:55 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdegreed%2F@54bfbd15790a473e628fc4b22c0d5a26e7f15f28
Security Audit — socket — degreed