tellmoney

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly consistent with its stated Tell.money integration purpose, and the CLI comes from an official npm package tied to the same vendor ecosystem. However, it routes authentication and financial-data access through Membrane rather than direct Tell.money APIs, uses mutable latest-version CLI execution, and enables broad proxied requests and potentially consequential payment actions. This looks like a legitimate but higher-trust integration pattern, not confirmed malware.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 05:10 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftellmoney%2F@8997c03f225a451fec2219fcc771d05721d893c2