ukg-pro-workforce-management

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent in purpose, and its CLI install source is relatively trustworthy, but it routes UKG authentication and API traffic through Membrane rather than directly to UKG. That intermediary credential/data flow is a meaningful risk and broader than a typical direct-service integration, though not enough to indicate confirmed malware.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:39 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fukg-pro-workforce-management%2F@772ece54e4ded7f3d067a45e7905582aff4552dc