smarterpay

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent as a Membrane-based SmarterPay integration, and its install path uses an official npm package rather than a raw downloader. The main risk is architectural: payment-related auth and data are routed through Membrane as an intermediary instead of directly to SmarterPay, and the CLI is unpinned and may store local secrets. That makes it higher trust and data-flow risk than a direct official API integration, but not clearly malicious.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 12:03 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsmarterpay%2F@d53f3bef2fc7b61f47a0ad7c0012fa04cfc064d7
Security Audit — socket — smarterpay