profitwell
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s stated purpose is ProfitWell integration, but its real operation depends on Membrane as an intermediary for authentication, action discovery, and API proxying. The install source looks legitimate enough for a normal supply-chain risk, but routing credentials and business data through a third-party broker is a meaningful data-flow and scope mismatch versus a direct official ProfitWell integration.
Confidence: 88%Severity: 68%
Audit Metadata