forescout

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities are mostly aligned, and the CLI comes from an official registry tied to the same vendor ecosystem. The main concern is data-flow integrity: Forescout authentication and actions are mediated through Membrane rather than directly through official Forescout APIs, creating third-party credential and data exposure. This is not clearly malicious, but it is a medium-risk brokered integration with unpinned CLI install instructions.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 2, 2026, 07:55 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fforescout%2F@0803dcd15fbdea6aae1b2f8ec35cc782026dddc5
Security Audit — socket — forescout