sertifi

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities are mostly coherent, and the CLI comes from an official npm package rather than an opaque binary. However, all Sertifi access and credentials are funneled through Membrane, a third-party intermediary, so data flow does not go directly to official Sertifi endpoints. This is not strong evidence of malware, but it is a meaningful security and trust-boundary expansion beyond a direct API integration.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
May 7, 2026, 06:54 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsertifi%2F@19d56f18c382262e7648a43f1e8f5846613c5e26
Security Audit — socket — sertifi