smartrecruiters

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities are mostly aligned, and the install path uses the official npm registry, but the core integration routes SmartRecruiters authentication and data access through Membrane rather than directly to SmartRecruiters. That third-party mediation is proportionate to the product's stated model yet creates medium security risk from credential/data concentration and unpinned CLI installation.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 03:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsmartrecruiters%2F@eea74ac80f359603a418abf98ae459b13c9cb50b