trinet

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match its stated TriNet integration purpose, and the CLI comes from a legitimate official npm package. The main risk is architectural: all authentication and TriNet data access are routed through Membrane, a third-party intermediary, which is broader trust than a direct official API integration and exposes sensitive HR data to an external platform. This is not confirmed malware, but it is medium risk due to third-party credential/data mediation and unpinned CLI installation.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:41 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftrinet%2F@763cfc07bd9415062e4486cb2df806273fd6348f