jumpcloud

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities match its stated JumpCloud integration purpose and the CLI source appears officially distributed via npm, so this is not overtly malicious. However, the skill depends on Membrane as a third-party intermediary for authentication and API proxying, meaning JumpCloud credentials and data flow through Membrane rather than directly to JumpCloud; combined with mutable `@latest` installs, this creates a meaningful but not clearly malicious trust and data-flow risk.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 04:06 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fjumpcloud%2F@61dc6ce4635dd36c7675a470a75c88f7dfbbc3af
Security Audit — socket — jumpcloud