paypro

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overtly malicious and uses an official npm-distributed CLI tied to the stated publisher ecosystem, but its purpose is internally inconsistent: it claims a PayPro payroll integration while linking to PayPal docs and describing a payments/invoicing data model. It also routes authentication and API activity through Membrane as a third-party intermediary rather than directly to the vendor API. Overall this looks like a templated or mislabeled integration skill with medium trust and data-flow risk, not confirmed malware.

Confidence: 89%Severity: 57%
Audit Metadata
Analyzed At
May 6, 2026, 08:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpaypro%2F@604c2f3e7be92f2a0639934414f5f0675e0f6fbe
Security Audit — socket — paypro