sap-hana

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent with its stated SAP S/4HANA integration purpose, and the install path uses an official npm package rather than an opaque binary or raw script. The main risk is architectural: authentication and SAP data/actions are mediated through Membrane's CLI/service, so enterprise credentials and records flow through a third-party platform, and the skill enables impactful business operations. This is not overtly malicious, but it carries medium risk due to third-party credential/data handling, mutable global install, and autonomous ERP action capability.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 07:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsap-hana%2F@296a0db6bf2b242cad24dae0124bb635e87ff28d
Security Audit — socket — sap-hana