referralrock

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's capabilities fit its purpose, and the CLI install source appears legitimate, but all ReferralRock access and authentication are mediated by Membrane rather than the official service directly. This creates a moderate third-party trust and data-routing risk, especially via the generic proxy feature, without clear evidence of malware or hidden exfiltration.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 10:38 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Freferralrock%2F@c176abca0ef1efa59bb6c420b7265ad4ad7bb207
Security Audit — socket — referralrock