payment-rails

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The overall footprint is mostly coherent for a Membrane-hosted integration skill, and the CLI install path is from an official npm package rather than an unverifiable binary. However, the skill routes all Payment Rails/Trolley access through Membrane instead of the service's official API, uses mutable latest-tag execution, and contains an inconsistent 'official docs' link to Rapyd. That combination raises medium trust and data-flow concerns, but not enough evidence for malicious intent.

Confidence: 82%Severity: 52%
Audit Metadata
Analyzed At
May 6, 2026, 07:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpayment-rails%2F@f1e8d066f2f43f96813f48de1ab0407395d03836
Security Audit — socket — payment-rails