nordic-api-gateway

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a Membrane-based Nordic API Gateway integration, and its install path is official npm rather than an unverified binary. The main concern is data-flow integrity and trust expansion: financial API access and auth are mediated through Membrane instead of going directly to the service, and the CLI is installed/executed at mutable `@latest` versions. No clear malware or covert exfiltration is shown, but the intermediary credential/data path and potential payment actions make this higher than low risk.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 6, 2026, 10:06 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnordic-api-gateway%2F@045f7c6cb26dc04aba68e0c21793a9d9a51e0d05
Security Audit — socket — nordic-api-gateway