teller

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent for a managed Teller integration, and the CLI install source appears official. The main risk is that all Teller authentication and data operations are mediated by Membrane, a third-party gateway, plus unpinned npm execution. This is not clearly malicious, but it meaningfully enlarges the trust boundary for financial data and workflow actions.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
May 5, 2026, 04:43 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fteller%2F@86577350b1fcd1e6262df0c62a4aa1b92be89cac