gladly

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose is coherent, and the CLI comes from an official registry with matching branding, so this is not confirmed malware. However, the core integration routes Gladly authentication and API access through Membrane as a third-party intermediary instead of directly to Gladly, and it relies on mutable `@latest` CLI execution. That makes the data flow and trust model higher risk than a direct Gladly integration.

Confidence: 85%Severity: 63%
Audit Metadata
Analyzed At
May 2, 2026, 07:11 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgladly%2F@33a7a04ff4da736962707268f67baecf6ea65a68
Security Audit — socket — gladly