ukg-pro-hcm

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities are broadly aligned with its UKG integration purpose, and the install path uses an official npm package rather than a raw downloader. However, it routes sensitive HR data and authentication through Membrane instead of direct UKG APIs, relies on a third-party CLI/service trust chain, uses an unpinned `@latest` install, and can dynamically create new actions. This is not confirmed malware, but it carries meaningful security and privacy risk due to credential/data mediation and expanded trust boundaries.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 01:02 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fukg-pro-hcm%2F@8ae7c7ff6a44a4dbc98944635101d2d047d5b36b
Security Audit — socket — ukg-pro-hcm