kustomer

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core behavior is coherent for a Membrane-based Kustomer integration, and the CLI install path is a legitimate npm package. The main concern is data-flow integrity: all Kustomer authentication and API activity are mediated by Membrane, a third-party service, rather than direct Kustomer endpoints. That expanded trust boundary makes the skill medium risk, but there is no strong evidence of malware, credential theft, or hidden behavior.

Confidence: 83%Severity: 52%
Audit Metadata
Analyzed At
May 2, 2026, 07:29 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fkustomer%2F@c76a6cf86d26bf8f40a4bdb943cf806fefd855be
Security Audit — socket — kustomer