shipstation

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities fit its ShipStation-management purpose and the CLI install path is a normal npm-based distribution, so this is not strongly indicative of malware. However, all ShipStation access and credential handling are mediated by Membrane rather than official ShipStation APIs, expanding the trust boundary to a third-party service and enabling significant account actions; that makes the skill moderately risky even though it is internally coherent.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
May 15, 2026, 08:44 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fshipstation%2F@054ac590bfea392847afdc454b0f3b94bfb8a152
Security Audit — socket — shipstation