stripe-identity

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, and the Membrane CLI appears to come from the expected publisher via npm. However, a Stripe Identity skill that routes authentication and API traffic through Membrane’s intermediary platform creates a significant third-party trust and data-flow risk, and the use of unpinned `@latest` installs adds supply-chain exposure. This looks more like a brokered integration than direct Stripe access; not confirmed malicious, but risk is medium due to credential handling and proxy-based data flow.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
May 6, 2026, 11:51 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fstripe-identity%2F@ce1ecfb54b8e6e83f198a98d98c16d245bd1025f
Security Audit — socket — stripe-identity