kartra

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent with its stated Kartra-integration purpose and uses an official-looking Membrane CLI from npm, but it routes credentials and API traffic through Membrane as an intermediary rather than directly to Kartra. That third-party credential/data handling is disclosed, not hidden, so this is not malicious, but it meaningfully raises trust and operational risk.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 03:03 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fkartra%2F@25b41039149adea3f3e5763e2342727d99452e39