shipcloud
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's capabilities broadly match its stated Shipcloud integration purpose, and the CLI comes from an official npm package, so this is not confirmed malware. However, all Shipcloud access and credentials are mediated through Membrane rather than direct official Shipcloud API use, creating a third-party data and credential routing concern; combined with mutable `@latest` installs, this makes the skill medium risk rather than benign.
Confidence: 84%Severity: 57%
Audit Metadata