expensify

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose broadly matches its capabilities, and the CLI install path looks official, but the integration relies on Membrane as a credential and API intermediary rather than talking directly to Expensify. That middleware design, combined with unpinned CLI installation and the ability to perform remote actions, makes the overall risk medium even without clear evidence of malicious intent.

Confidence: 82%Severity: 57%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:41 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fexpensify%2F@3ce981384d03b91e5c8caaf46763848fabc0c319