tribe-payments
Warn
Audited by Socket on May 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is not overtly malicious and uses an official npm package from the same vendor, but its real footprint is a Membrane integration layer rather than a direct Tribe Payments integration. The main concern is third-party mediation of authentication and payment-related data, plus an unusually broad claimed object scope that exceeds a narrowly scoped Tribe Payments skill.
Confidence: 86%Severity: 56%
Audit Metadata