power-automate

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated purpose, and the CLI comes from an official registry, so this is not strong evidence of malware. However, the integration routes authentication, credentials, and Power Automate operations through Membrane rather than official Microsoft endpoints, creating a third-party trust and data-flow layer with moderate security risk.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
May 1, 2026, 05:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpower-automate%2F@cc448be14cfe90db0bbfa09eb130656b0af2c045
Security Audit — socket — power-automate