finix

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align, and the CLI install path appears to be official npm-based rather than a deceptive payload. The main concern is data-flow integrity and trust expansion: Finix access and credentials are mediated by Membrane, a third-party integration layer, so payment data and auth do not flow directly to Finix. This is plausible for an integration skill but increases risk, especially with unpinned CLI installs and broad action/proxy capability against a payments system.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:40 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffinix%2F@6e37270fe01bfdc6cc79aee8c277a3bb54837071
Security Audit — socket — finix