postman

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent as a Postman integration, and its CLI install path appears to be official npm distribution, so it is not confirmed malware. However, it materially expands trust by routing authentication and Postman operations through Membrane’s third-party CLI/service, including server-side action discovery/building, which makes the data flow and credential handling broader than a direct Postman skill.

Confidence: 83%Severity: 62%
Audit Metadata
Analyzed At
May 5, 2026, 08:58 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpostman%2F@4aeb97154915b6021f761125c968c54822888085
Security Audit — socket — postman