tellent
Warn
Audited by Socket on May 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The overall footprint is mostly consistent with a Tellent integration, and the CLI comes from the official npm scope. The main concern is data-flow integrity: Tellent access is mediated through Membrane's proxy and account system rather than direct official Tellent endpoints, creating third-party trust and visibility into HR data. Unpinned `@latest` installs add moderate supply-chain risk, but there is no clear evidence of malware, credential theft, or covert behavior.
Confidence: 83%Severity: 57%
Audit Metadata