sharpspring

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated SharpSpring integration purpose, and the install path uses an official npm package rather than a raw downloader. The main risk is architectural: all authentication and API access are mediated by the Membrane CLI/service, so CRM credentials and data depend on a third-party platform outside SharpSpring. Combined with unpinned `@latest` installation and broad proxy request capability, this is medium risk but not clearly malicious.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 07:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsharpspring%2F@a4536352b68f5360a91dc5cd17e9024bb6801d52
Security Audit — socket — sharpspring