hellosign

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose matches HelloSign management, and its CLI install path is consistent with the Membrane publisher, so this is not clearly malicious. However, the integration is materially mediated by Membrane rather than direct HelloSign APIs, expanding third-party data access and enabling externally consequential actions like sending or canceling signature requests. Overall this is a coherent but medium-risk proxy-style integration skill.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 3, 2026, 10:28 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhellosign%2F@77392ad8069a86f699bac91a15ea87289da4f1c9
Security Audit — socket — hellosign