pendo

Warn

Audited by Socket on Sep 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose broadly matches its capabilities, and the CLI appears to come from an official npm package, so this is not malware. However, the integration is really a Membrane-mediated Pendo workflow: authentication, credential refresh, action execution, and proxy requests are all delegated to a third-party platform, and the install uses mutable `@latest` commands. The footprint is coherent but introduces medium supply-chain and data-flow trust risk.

Confidence: 90%Severity: 56%
Audit Metadata
Analyzed At
Sep 21, 2026, 11:33 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpendo%2F@fc7482f16c41e661b4613b1352a460cfee588d1729e214cac434eabf5d85a223
Security Audit — socket — pendo