espocrm

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated EspoCRM purpose and uses an official npm package, but it routes authentication and CRM operations through Membrane’s intermediary service instead of EspoCRM directly. That brokered data flow, combined with dynamic action creation and unpinned CLI install, creates moderate security risk without enough evidence for malicious intent.

Confidence: 87%Severity: 57%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:52 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fespocrm%2F@62c6b75c457e3d40d85669db6c1cbcaa7fa88bb2
Security Audit — socket — espocrm