procore

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities mostly align, and the CLI install path appears official. However, it routes authentication, credentials, and Procore data through Membrane as an intermediary platform, and it enables remote action generation/execution with potential write access to real business systems. This is not clearly malicious, but the trust and data-flow footprint is broader than a direct Procore integration and warrants medium risk.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:22 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fprocore%2F@298d34742191b958487ebb265040eb12f66494ca
Security Audit — socket — procore