sap-c4c
Warn
Audited by Socket on May 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's core function is coherent with SAP C4C integration, and the CLI install path is relatively normal via npm. However, all authentication, action discovery, dynamic action generation, and SAP data access are routed through Membrane rather than official SAP APIs, creating a significant third-party trust boundary for enterprise CRM data. This is not confirmed malware, but it is a medium-risk integration skill with notable credential/data mediation and unpinned dependency concerns.
Confidence: 87%Severity: 56%
Audit Metadata