jupiterone

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent and not overtly malicious, but it routes JupiterOne authentication and API traffic through Membrane’s third-party platform instead of direct JupiterOne APIs. That intermediary credential/data handling makes this a medium-risk integration despite otherwise legitimate npm-based installation and aligned functionality.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 05:27 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fjupiterone%2F@e7f909f0867cef83c0cd1d0976a63ef71b6db695
Security Audit — socket — jupiterone