ukg-pro
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is coherent as a UKG automation wrapper, but it relies on a third-party intermediary (Membrane) for authentication and data access instead of direct UKG APIs. Install source is relatively trustworthy and same-vendor via npm, so this is not strong malware evidence, but the unpinned CLI execution and credential/data routing through Membrane create a meaningful medium security risk.
Confidence: 84%Severity: 58%
Audit Metadata