easypost

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent as a Membrane-based EasyPost integration, and the install source appears legitimate. Main risk comes from third-party mediation through Membrane, unpinned CLI installation, and the ability to trigger real-world shipping actions; this is more a trust-boundary and execution-scope concern than confirmed malware.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 09:56 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Feasypost%2F@e2c2f9a7e1cd349884ceab15d48da083253ece7e
Security Audit — socket — easypost