jobscore

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated JobScore integration purpose, and the CLI comes from an official npm package tied to the same vendor. However, it routes authentication and API traffic through Membrane rather than directly to JobScore, creating third-party credential/data exposure, and the incorrect official-docs link undermines confidence. This is not confirmed malware, but it carries medium security risk due to intermediary data flow and mutable CLI installation.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 03:21 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fjobscore%2F@13874d0ecea387d2392e8385ef007e1c4e7459cd