lemlist

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is suspicious rather than overtly malicious. Its purpose matches Lemlist automation, but the actual footprint is broader than necessary because authentication, requests, and action execution are routed through Membrane's third-party CLI and proxy instead of directly to Lemlist's official API. That creates medium-high security risk from credential forwarding and intermediary data flow, though there is no clear evidence of deliberate malware or stealth.

Confidence: 84%Severity: 71%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:41 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Flemlist%2F@0fc267c38c7f6675ff0f55bb676b367775029d98