shipcloud

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated Shipcloud integration purpose, and the CLI comes from an official npm package, so this is not confirmed malware. However, all Shipcloud access and credentials are mediated through Membrane rather than direct official Shipcloud API use, creating a third-party data and credential routing concern; combined with mutable `@latest` installs, this makes the skill medium risk rather than benign.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Apr 29, 2026, 07:41 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fshipcloud%2F@3f5715d674c1dc83b87eadb5533beee26d29838b
Security Audit — socket — shipcloud