smooch

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities mostly align, and the CLI install path is from an official npm package rather than an unverifiable binary. However, the integration routes authentication and Smooch data through Membrane as a third-party intermediary instead of the official Sunshine Conversations API, and the skill explicitly steers users toward that brokered path. This is a coherent product model, not confirmed malware, but it creates medium security risk due to credential/data delegation and an unpinned external CLI dependency.

Confidence: 87%Severity: 57%
Audit Metadata
Analyzed At
May 6, 2026, 11:51 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsmooch%2F@f067f19d336bef82c67caebff89681217b72f463
Security Audit — socket — smooch