onespan

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities broadly match its purpose, and installation uses an official npm package rather than an unverifiable binary. However, the integration is not a direct OneSpan client: authentication, credential storage, and API requests are mediated by Membrane infrastructure, which creates a nontrivial third-party data flow that users may not expect from a vendor-specific skill.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 12:59 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fonespan%2F@1aa22a8b50f2b88d3ec98c06dc784b6fdb54a4f8
Security Audit — socket — onespan