ibm-api-connect

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities generally fit its IBM API Connect purpose, and the CLI comes from an official npm package rather than an unverifiable binary. However, all authentication and API operations are routed through Membrane as an intermediary, which is a meaningful trust and data-flow expansion beyond a direct IBM integration, and the install is unpinned. This is not confirmed malware, but it is a moderate-risk brokered integration that warrants caution.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
May 1, 2026, 03:49 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fibm-api-connect%2F@80e2f0479f36ffa4092fb2b91a0ddd7249ee92fa
Security Audit — socket — ibm-api-connect