follow-up-boss
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's CRM capabilities broadly match its purpose, and the CLI install path is from an official registry, so this is not overtly malicious. However, the core design routes authentication, credentials, and Follow Up Boss API traffic through Membrane as a third-party intermediary, and it encourages installing and trusting that CLI globally with a mutable version. The footprint is coherent but introduces medium security risk due to credential/data brokerage and indirect API access.
Confidence: 86%Severity: 56%
Audit Metadata