oracle-cloud-hcm

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent for Oracle Cloud HCM integration and uses an official npm-distributed CLI from the same vendor, so this is not strong malware evidence. However, all authentication and API traffic are brokered through Membrane rather than going directly to Oracle, which creates meaningful third-party credential and HR data exposure; combined with mutable @latest installs, this makes the skill medium risk.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:39 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Foracle-cloud-hcm%2F@39e821e36a180bf2934da6a0110b0190a4dd4a93