follow-up-boss

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's CRM capabilities broadly match its purpose, and the CLI install path is from an official registry, so this is not overtly malicious. However, the core design routes authentication, credentials, and Follow Up Boss API traffic through Membrane as a third-party intermediary, and it encourages installing and trusting that CLI globally with a mutable version. The footprint is coherent but introduces medium security risk due to credential/data brokerage and indirect API access.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:54 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffollow-up-boss%2F@5f56a59c20b202c8b632e7904654ead336e0d532