ftrack

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose matches FTrack management, and the CLI install source is legitimate, but the actual data flow is a third-party Membrane proxy/connection layer rather than direct FTrack API use. That makes the scope broader than a simple FTrack client and raises medium risk around credential/data mediation and agent-driven write actions, though there is no clear evidence of outright malware.

Confidence: 89%Severity: 57%
Audit Metadata
Analyzed At
May 2, 2026, 05:49 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fftrack%2F@e9394f890985ccb97888be3bc52a9cea436f6838