moonclerk

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose is plausible, and the CLI comes from an official npm package tied to the publisher, so this is not confirmed malware. However, the integration is architected around Membrane as a third-party intermediary for authentication and API access instead of direct MoonClerk API use, which creates medium risk around credential delegation and data flow integrity; combined with unpinned CLI installs, this makes the skill internally coherent but broader and riskier than a direct MoonClerk connector.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 11:52 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmoonclerk%2F@954f0cd855e63243c7dea3ccd7dd4d4d112a0a38
Security Audit — socket — moonclerk