fivetran

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities fit its stated Fivetran-management purpose, and the CLI install path is reasonably consistent with the publisher via npm. The main risk is architectural: all authentication and API operations are mediated through Membrane rather than direct Fivetran endpoints, creating third-party credential and data-flow exposure, plus the skill enables impactful administrative actions. This is not confirmed malicious, but it is medium risk and should be trusted only if Membrane is an explicitly accepted intermediary.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 08:36 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffivetran%2F@5fd98f9bc645f6fd39f7ab757c7e7102d76157cc
Security Audit — socket — fivetran