faktoora
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is purpose-aligned and uses an official npm-distributed Membrane CLI, so it does not look outright malicious. However, it routes Faktoora authentication and API traffic through Membrane as a third-party intermediary, uses an unpinned global CLI install, and enables real external mutations in an accounting system; this makes it higher-risk than a direct API guide but still broadly coherent with its stated purpose.
Confidence: 87%Severity: 58%
Audit Metadata