helpwise

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent with its stated Helpwise integration purpose and uses an official npm-distributed Membrane CLI, so it does not look malicious. However, all Helpwise authentication and API traffic are funneled through Membrane as an intermediary, and the skill enables impactful customer-support actions plus mutable latest-version CLI execution. That makes it medium risk even though the capability set is purpose-aligned.

Confidence: 89%Severity: 57%
Audit Metadata
Analyzed At
May 1, 2026, 12:07 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhelpwise%2F@3deab827be306050059c393f9f013b2fe86c1df9
Security Audit — socket — helpwise