jobnimbus
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose broadly matches CRM integration, and the CLI comes from npm rather than an unknown binary source, but the real data flow is through Membrane as a third-party proxy and credential manager instead of directly to JobNimbus. That intermediary architecture is a medium risk trust and data-governance concern, amplified by the unpinned `@latest` install, but there is not enough evidence of overtly malicious behavior.
Confidence: 84%Severity: 58%
Audit Metadata