google-postmaster-tools

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities mostly align, and the CLI install path is a normal npm-based same-vendor dependency rather than a clear malware pattern. However, the core data flow and auth model route Google Postmaster access through Membrane’s third-party platform instead of direct Google APIs, creating moderate credential-forwarding and data-intermediation risk that is broader than a minimal Google-only integration.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 12:08 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgoogle-postmaster-tools%2F@787014aaf9e07e2a6fe24d30e6d492049b20ee00
Security Audit — socket — google-postmaster-tools