pipeline-crm

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's general CRM functionality is coherent, and the CLI install path is from an official npm package tied to the same vendor. However, the core data and auth flow is routed through Membrane as a managed intermediary rather than directly to PipelineCRM, which is a material data-flow integrity and credential-forwarding concern for a skill presented as a PipelineCRM integration.

Confidence: 89%Severity: 62%
Audit Metadata
Analyzed At
May 2, 2026, 05:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpipeline-crm%2F@0a4107fb978cffb2a278d378c0cc7cccb52cf52f
Security Audit — socket — pipeline-crm