jobscore
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities broadly match its stated JobScore integration purpose, and the CLI comes from an official npm package tied to the same vendor. However, it routes authentication and API traffic through Membrane rather than directly to JobScore, creating third-party credential/data exposure, and the incorrect official-docs link undermines confidence. This is not confirmed malware, but it carries medium security risk due to intermediary data flow and mutable CLI installation.
Confidence: 87%Severity: 58%
Audit Metadata