paygreen
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose and capabilities are mostly coherent, and the CLI install path is from a legitimate npm package rather than an unverified binary. The main concern is data-flow integrity: all PayGreen access, authentication, and action execution are mediated by Membrane instead of the official PayGreen API, so users must trust a third-party platform with payment-related access and data.
Confidence: 84%Severity: 58%
Audit Metadata