nutshell

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's basic CRM functionality is plausible, and its install path is relatively trustworthy, but its actual data flow is centered on Membrane as an intermediary. Because authentication, credential refresh, and even raw Nutshell API requests are routed through a third-party platform instead of directly to official Nutshell APIs, the skill has medium-high security risk despite low evidence of outright malware.

Confidence: 89%Severity: 69%
Audit Metadata
Analyzed At
May 2, 2026, 04:03 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnutshell%2F@772a3bdf5b5eca472c30d40f302d0941ecf71148