demandbase

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is plausible, and the CLI source appears same-vendor and npm-hosted, but the actual footprint is a Membrane gateway skill rather than a direct Demandbase integration. The main concern is third-party mediation of authentication, credential refresh, and all Demandbase data flows through Membrane, plus an unpinned `@latest` CLI install.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
May 3, 2026, 07:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdemandbase%2F@67baaf776a03e881dc65b35f4b823aa52ba3cf0e
Security Audit — socket — demandbase