moosend

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities align with Moosend management, and the CLI appears to be the publisher's legitimate npm package, so this is not confirmed malware. However, the skill materially expands trust by requiring a Membrane account, routing auth and API traffic through Membrane, and enabling impactful actions like sending campaigns; combined with unpinned CLI install/execution, that makes the overall risk medium and the data flow less direct than the stated Moosend integration might imply.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:55 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmoosend%2F@ad91c70ca69d5e49a79dd46e052ac999f98104cd
Security Audit — socket — moosend