respondio

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated Respond.io integration purpose, and the CLI install source appears official via npm. However, the core data flow is mediated through Membrane rather than direct Respond.io API use, so authentication and API traffic are delegated to a third-party platform. That makes the skill internally coherent but medium risk due to intermediary credential/data handling and unpinned CLI installation.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 04:07 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Frespondio%2F@b919c5782b45e9dc9da96f59a11d5d0b4cc88641
Security Audit — socket — respondio