tribe-payments

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overtly malicious and uses an official npm package from the same vendor, but its real footprint is a Membrane integration layer rather than a direct Tribe Payments integration. The main concern is third-party mediation of authentication and payment-related data, plus an unusually broad claimed object scope that exceeds a narrowly scoped Tribe Payments skill.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 10:25 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftribe-payments%2F@5c47809b5e52f072869537df55d159f74870c757
Security Audit — socket — tribe-payments