omnisend

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is broadly aligned with its stated Omnisend-integration purpose and uses an official-looking npm-distributed CLI, so it is not clearly malicious. The main risk is architectural: authentication and API traffic are mediated by Membrane rather than going directly to Omnisend, creating third-party trust and data-flow exposure, plus some supply-chain risk from installing an unpinned `@latest` CLI. Overall this is better classified as suspicious/medium-risk rather than benign or malware.

Confidence: 84%Severity: 50%
Audit Metadata
Analyzed At
Apr 30, 2026, 09:15 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fomnisend%2F@21a5e5cdcf11814659b24a7a6f42c4c8077e6ae0
Security Audit — socket — omnisend