paykickstart

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align, and the CLI comes from an official npm package rather than an unverifiable binary. However, all PayKickstart authentication and API traffic are funneled through Membrane's intermediary service, so credentials and data are forwarded to a third party instead of going directly to PayKickstart. This is disclosed and may be legitimate for Membrane's platform, but it materially raises trust and data-flow risk beyond a direct API integration.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:21 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpaykickstart%2F@73c7e18b445a9a6699e523f647d37984b588d5b5
Security Audit — socket — paykickstart