shipday

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent as a Membrane-based Shipday integration and uses an official npm-published CLI, so it does not look like confirmed malware. But it routes authentication and Shipday operations through Membrane rather than Shipday's official API, creating a meaningful third-party data and credential trust concern; combined with mutable `@latest` installs, this makes the skill medium risk rather than benign.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 3, 2026, 04:35 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fshipday%2F@6490c22cc2aec8d9eba404403cf44e2ea958f35f
Security Audit — socket — shipday