pipefy

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities fit its stated Pipefy integration purpose, and the CLI comes from npm rather than an opaque binary source. However, all authenticated Pipefy access is intentionally funneled through Membrane’s infrastructure, creating a third-party credential and data intermediary that is broader than direct Pipefy API use. This is not confirmed malware, but it is a medium-risk trust-boundary expansion with moderate supply-chain and data-routing concerns.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 04:08 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpipefy%2F@2fed7ab0a1d4c5d57325297b181b839453320e5b