profitwell

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose is ProfitWell integration, but its real operation depends on Membrane as an intermediary for authentication, action discovery, and API proxying. The install source looks legitimate enough for a normal supply-chain risk, but routing credentials and business data through a third-party broker is a meaningful data-flow and scope mismatch versus a direct official ProfitWell integration.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:41 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fprofitwell%2F@2014cb11110dd3ba9ca6b6ba810620717d4af652
Security Audit — socket — profitwell