freshmarketer
Warn
Audited by Socket on May 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly aligned with its stated Freshmarketer integration purpose and uses an official npm package, so it does not look outright malicious. However, all authentication and data access are funneled through Membrane as an intermediary rather than directly to Freshworks, and the CLI install is unpinned. This is a coherent third-party integration pattern, but it carries medium trust and data-flow risk because business data and credentials are delegated to Membrane-managed services.
Confidence: 84%Severity: 56%
Audit Metadata