namely

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities broadly match its Namely integration purpose, and the CLI install path is from an official npm package. The main risk is data-flow integrity: Namely authentication and HR data are routed through Membrane as a third-party gateway/proxy, which is disproportionate for users expecting direct official API interaction and raises credential/data handling concerns even though the behavior is disclosed.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:14 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnamely%2F@a444f2847d331112c0840309a86b874b3c22bc4a
Security Audit — socket — namely