paycaptain

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent as a Membrane-based PayCaptain integration and uses an official npm-distributed CLI, so it is not confirmed malware. However, it routes authentication, action generation, and PayCaptain data access through Membrane rather than directly to official PayCaptain endpoints, creating intermediary trust and credential/data-flow risk; mutable `@latest` installs add supply-chain exposure.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 09:42 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpaycaptain%2F@a4016e4f273bd16d0850374baeb2caa850cfc17e
Security Audit — socket — paycaptain