jobber

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its Jobber integration purpose, and the CLI install path appears official, so there is no clear malware signal. However, all authentication and API access are mediated through Membrane rather than directly to Jobber, creating meaningful third-party data handling and action-execution risk that is larger than a simple direct API integration.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fjobber%2F@7b30dae4d073cd92c46eec02ffce2f63951388cd
Security Audit — socket — jobber