truelayer

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent for a Membrane-based TrueLayer integration and uses an official npm package, but it routes banking data and auth through Membrane instead of direct TrueLayer APIs and can enable real financial actions. This is not confirmed malware, but the third-party intermediary data flow and payment capability make the overall risk medium.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
May 10, 2026, 01:05 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftruelayer%2F@b169c64fc098135fe77a73c5ba4fc6df1e789f58
Security Audit — socket — truelayer