flutterwave

Warn

Audited by Socket on Sep 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its Flutterwave-integration purpose, and the CLI comes from an official npm package rather than an obviously malicious installer. However, all authentication and API traffic are routed through Membrane, a third-party intermediary rather than direct Flutterwave endpoints, and the skill enables high-impact financial actions. This is not confirmed malware, but it is medium risk due to credential/data mediation and autonomy over payment operations.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Sep 21, 2026, 09:18 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fflutterwave%2F@3771ec4101c98715b38b412960a35e976ff29f6a811622feb735b55877146208
Security Audit — socket — flutterwave