qualiobee

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is professionally presented and uses an official npm-distributed CLI from the same publisher, so this is not confirmed malware. However, the stated purpose is a Qualiobee integration while the actual data flow and auth model route everything through Membrane, a third-party intermediary that manages credentials and handles actions server-side. That mismatch raises medium security concerns around credential forwarding, data visibility, and broadened scope.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 8, 2026, 12:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fqualiobee%2F@a18bcc5f56b74fecb1073bcafdd12e131966a1c0
Security Audit — socket — qualiobee