gorgias

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent as a Membrane-based Gorgias integration, and the CLI installer appears official via npm, so this is not confirmed malware. However, it materially expands trust by routing authentication, credentials, and Gorgias operations through Membrane rather than directly to official Gorgias endpoints, and it uses mutable `@latest` CLI execution. That makes the skill medium risk and somewhat disproportionate for a simple service integration.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
May 9, 2026, 01:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgorgias%2F@22333374ecdaab470b69ec6cbbf5be1955dccc37
Security Audit — socket — gorgias