tellent

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The overall footprint is mostly consistent with a Tellent integration, and the CLI comes from the official npm scope. The main concern is data-flow integrity: Tellent access is mediated through Membrane's proxy and account system rather than direct official Tellent endpoints, creating third-party trust and visibility into HR data. Unpinned `@latest` installs add moderate supply-chain risk, but there is no clear evidence of malware, credential theft, or covert behavior.

Confidence: 83%Severity: 57%
Audit Metadata
Analyzed At
May 2, 2026, 06:19 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftellent%2F@3b8dac9c3a33f5f5ef0b115d627674c85eb89f3b