sap-ariba

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are broadly aligned, and the CLI comes from an official registry, but the integration routes SAP Ariba authentication and data through Membrane rather than direct SAP APIs and relies on an unpinned third-party CLI/service. This is not confirmed malicious, but it introduces meaningful third-party trust and data-flow risk for enterprise procurement data.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 29, 2026, 01:00 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsap-ariba%2F@646991388fae9837cb6d9df780e3227857da1afc
Security Audit — socket — sap-ariba