sparkpost

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, but it routes SparkPost authentication and API traffic through Membrane rather than using SparkPost's official direct API flow. The install source looks legitimate and not overtly malicious, yet the intermediary account/CLI/proxy model creates medium security risk and credential/data exposure concerns disproportionate to a simple SparkPost integration.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:39 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsparkpost%2F@bdd604efb9a72bf96da30b783f7d16949a3f615f
Security Audit — socket — sparkpost