espocrm
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is broadly aligned with its stated EspoCRM purpose and uses an official npm package, but it routes authentication and CRM operations through Membrane’s intermediary service instead of EspoCRM directly. That brokered data flow, combined with dynamic action creation and unpinned CLI install, creates moderate security risk without enough evidence for malicious intent.
Confidence: 87%Severity: 57%
Audit Metadata