mparticle

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and commands are mostly coherent, and the CLI comes from the official npm registry, so this is not overtly malicious. However, it routes MParticle authentication and data through Membrane as a third-party intermediary instead of the official MParticle API, creating meaningful credential and data-flow trust concerns; combined with the mutable @latest install, this makes the skill medium risk rather than benign.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:41 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmparticle%2F@0749a50836ed178ea179ba18d8ae91bb0221ffcd
Security Audit — socket — mparticle