onepagecrm

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities are mostly coherent, and the CLI install source appears legitimate and same-vendor via npm. The main concern is data-flow integrity: all OnePageCRM access and credential handling are routed through Membrane rather than directly to OnePageCRM, which is disclosed but introduces a third-party intermediary for both data and auth. This is not fundamentally incompatible with the skill’s stated purpose, so it does not rise to malicious, but it carries medium risk due to credential/data centralization and the unpinned `npx @latest` example.

Confidence: 88%Severity: 54%
Audit Metadata
Analyzed At
May 1, 2026, 02:31 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fonepagecrm%2F@09099189bf5207a2017b72c28397881a24f89f35
Security Audit — socket — onepagecrm