knowbe4

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent as a Membrane-based KnowBe4 integration, and its CLI install source appears legitimate via official npm. However, it routes authentication and KnowBe4 access through Membrane rather than directly to KnowBe4, creating a significant third-party credential and data trust boundary; this is not outright malicious, but it is a meaningful security and data-flow risk that should be understood before use.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 08:51 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fknowbe4%2F@60003d7ade91c09577031e8d4c330fcf5339a76a
Security Audit — socket — knowbe4