teamcity

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, and the CLI install path is relatively legitimate via npm, but the integration is mediated by Membrane rather than direct TeamCity APIs. That third-party credential and data proxying is a meaningful trust expansion and makes the data flow less proportionate than a direct TeamCity skill, though not enough to call it malicious.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:20 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fteamcity%2F@2b5d6643db6fe40b434b98c5a226311588293b212b0ab201d812c72bbc57bc58
Security Audit — socket — teamcity