engagebay

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's basic purpose is coherent, and the installer is not obviously malicious, but the real integration path is a third-party Membrane proxy/CLI rather than direct EngageBay API usage. That intermediary data flow and credential handling model materially raises trust and privacy risk, especially with an unpinned global CLI and dynamic action creation.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:18 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fengagebay%2F@5a6c94cea581be84d6853c47a5e2fb82215079a2
Security Audit — socket — engagebay