setmore

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose broadly matches Setmore integration, and the CLI install source appears legitimate, but the actual data flow routes authentication and API traffic through Membrane instead of directly to Setmore. That third-party credential and data mediation is a meaningful integrity and trust risk, though not confirmed malware.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Apr 28, 2026, 07:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsetmore%2F@f680fc5835255a0174f99a4f30dbfb5502e75743
Security Audit — socket — setmore