mailchimp

Warn

Audited by Socket on Sep 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, but it routes Mailchimp authentication and API traffic through a third-party Membrane CLI/service instead of Mailchimp's direct API. The install source is legitimate npm rather than an unverifiable binary, so this is not confirmed malware, but the intermediary credential/data flow and mutable `@latest` install make the skill medium risk.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Sep 24, 2026, 10:33 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmailchimp%2F@ad631c329f704b0188000d8885c2e6458096accf5e0b3f3c4962961ad5822955
Security Audit — socket — mailchimp