maintainx

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities mostly match its MaintainX integration purpose, and the install path uses an official npm package rather than an unverifiable binary. However, all authentication and API traffic are funneled through Membrane as a third-party intermediary instead of direct MaintainX APIs, which raises medium data-flow and trust concerns despite being openly disclosed.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 11:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmaintainx%2F@f8c7b8e1b6658250ec6845a30dbf240ec227dab7