junip

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent for Junip access, and the CLI appears to be an official Membrane tool from npm, so this is not strong evidence of malware. However, the skill routes authentication and data access through Membrane's managed platform instead of Junip directly, dynamically creates actions, and relies on an unpinned global CLI install, making the overall security posture moderately risky for a narrowly described SaaS integration.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 08:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fjunip%2F@6ae9791230f38168ce4744b55510a1432d2b13cd