usercom

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities are mostly aligned, and the CLI comes from an official same-vendor npm package, so this is not overt malware. However, the core integration routes User.com authentication and data operations through Membrane as a third-party intermediary instead of direct official User.com APIs, which creates a meaningful data-flow and trust-boundary concern; combined with unpinned CLI execution, this makes the skill medium risk rather than benign.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
May 7, 2026, 06:44 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fusercom%2F@9e91164816c56dc49153a8a44eea27b234387811
Security Audit — socket — usercom