ukg-ready

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is coherent with its stated UKG Ready integration purpose and uses an official Membrane CLI from npm, so it is not malicious. The main risk is architectural: sensitive UKG authentication and data are routed through Membrane as a third-party intermediary, plus the CLI install is globally unpinned and the skill can trigger real HR actions.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 1, 2026, 06:42 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fukg-ready%2F@1f8903204519800d756e3191b4b32311213319df
Security Audit — socket — ukg-ready