okta

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities match its stated Okta admin purpose, and the CLI comes from a plausible first-party npm package, so this is not strong evidence of malware. However, all authentication and API access are funneled through Membrane rather than direct Okta endpoints, creating a third-party trust boundary for identity data, and the skill enables sensitive admin actions with real operational impact.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
May 8, 2026, 03:08 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fokta%2F@f46c983cade4af90279c25a5043f312b17b960d6
Security Audit — socket — okta