meesho

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely coherent as a Membrane-based Meesho integration and uses an official npm-distributed CLI from the same publisher, so it does not look malicious. However, all authentication and API traffic are routed through Membrane instead of directly to official Meesho endpoints, and the generic connector/proxy model plus unpinned `@latest` CLI usage create meaningful trust and data-flow risk beyond a narrowly scoped Meesho skill.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:41 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmeesho%2F@1a4e6b6debdc6416be01c7e1b3f84c9fcc115aee
Security Audit — socket — meesho