pendo
Warn
Audited by Socket on Sep 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's purpose broadly matches its capabilities, and the CLI appears to come from an official npm package, so this is not malware. However, the integration is really a Membrane-mediated Pendo workflow: authentication, credential refresh, action execution, and proxy requests are all delegated to a third-party platform, and the install uses mutable `@latest` commands. The footprint is coherent but introduces medium supply-chain and data-flow trust risk.
Confidence: 90%Severity: 56%
Audit Metadata