hubspot

Warn

Audited by Socket on Sep 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent for a HubSpot integration and uses an official npm-published CLI, so it is not malware-like. The main risk is architectural: HubSpot credentials and API traffic are mediated by Membrane rather than going directly to HubSpot, expanding the trust boundary and making data flow less direct than the skill title alone implies.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Sep 21, 2026, 04:08 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhubspot%2F@6ae77f85011647ad48192c970cb3069bf3dce1c52a0f4eb1671751fac65df95c
Security Audit — socket — hubspot