sap-c4c

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core function is coherent with SAP C4C integration, and the CLI install path is relatively normal via npm. However, all authentication, action discovery, dynamic action generation, and SAP data access are routed through Membrane rather than official SAP APIs, creating a significant third-party trust boundary for enterprise CRM data. This is not confirmed malware, but it is a medium-risk integration skill with notable credential/data mediation and unpinned dependency concerns.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 03:50 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsap-c4c%2F@2cd85b599c26b4de2d30c9955cfec1338f71c256
Security Audit — socket — sap-c4c