punchh

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's stated purpose matches its capabilities, and the CLI install path appears officially documented via npm, so this is not outright malicious. However, the skill routes Punchh access and credentials through Membrane rather than the official Punchh API directly, creating a third-party credential/data intermediary and a moderate trust boundary; combined with mutable `@latest` CLI installation, this makes the overall risk medium.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
May 1, 2026, 12:07 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpunchh%2F@bc3532c86d016464dff453934c85c65b7d3fa7fa
Security Audit — socket — punchh