mercado-pago

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent with its stated Mercado Pago integration purpose, and the CLI install path appears to be an official npm package rather than an unverifiable binary. However, all access is routed through Membrane as a third-party intermediary, and the skill enables real financial actions with a mutable CLI version and no explicit per-action approval guardrails. This is better classified as a medium-risk third-party brokered integration, not confirmed malware.

Confidence: 87%Severity: 53%
Audit Metadata
Analyzed At
Apr 29, 2026, 12:05 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmercado-pago%2F@f1ad1697bff38159d01aaeb5e5c7a2849a2a262f
Security Audit — socket — mercado-pago