marqeta

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent as a Marqeta integration, and its CLI install path appears to be the publisher's official npm package. However, all authentication and API traffic are mediated by Membrane rather than going directly to Marqeta, creating a third-party trust and data-flow boundary that is broader than a typical direct integration.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Apr 28, 2026, 08:15 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmarqeta%2F@25c26c2f7be18777a9fc6bc6f59f954048e0be09
Security Audit — socket — marqeta