lob

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent as a Lob integration helper, and the CLI install source is legitimate npm rather than an unverifiable binary. However, the skill materially changes the trust model by routing authentication and API traffic through Membrane, a third-party intermediary, so credentials and Lob data do not flow directly to official Lob endpoints. That intermediary design is disclosed and may be intentional, but it is still a meaningful data-flow and credential-forwarding risk beyond a simple Lob connector.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:39 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Flob%2F@1fa63b3f0536e4910348a4c605b441a70e152f78
Security Audit — socket — lob