finicity

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's basic Finicity purpose is plausible, and the CLI install source is an official npm package, but the real integration is mediated through Membrane rather than directly with Finicity. That intermediary auth and proxy model expands trust, forwards financial-data access through a third party, and is only partially aligned with the stated single-service purpose.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffinicity%2F@b17de37bb7011014aae89d3da1995fea30c80e59
Security Audit — socket — finicity