shiphero

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities are mostly aligned, and the CLI comes from an official npm package tied to the stated vendor, so this is not strong evidence of malware. However, the skill requires a third-party Membrane account, routes ShipHero authentication and data access through Membrane rather than direct official ShipHero APIs, and uses unpinned `@latest` CLI execution; those factors make the trust and data-flow footprint broader than a simple ShipHero integration.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
May 1, 2026, 04:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fshiphero%2F@f506e7854902d1c917f6a6d7081cac5a2d84c3ff
Security Audit — socket — shiphero