melissa-data

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly purpose-aligned and uses an official npm-distributed first-party CLI, so it does not look malicious. However, it centralizes Melissa authentication and data operations through Membrane rather than Melissa’s official API endpoints, creating a third-party credential/data mediation layer with moderate trust and privacy risk; the unpinned global CLI install adds low supply-chain risk.

Confidence: 85%Severity: 53%
Audit Metadata
Analyzed At
May 3, 2026, 09:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmelissa-data%2F@98403586000bf6f1fbce1203dbac35cf3ddba374