uservoice

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose broadly matches UserVoice automation, and the CLI source appears to be the publisher's official npm package. However, all authentication and API access are routed through Membrane rather than directly to official UserVoice endpoints, creating third-party credential/data mediation that is disproportionate for a plain UserVoice skill and raises trust and data-flow concerns.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:10 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fuservoice%2F@85b1696d3c80bce54940cf483a4f2777d3236451
Security Audit — socket — uservoice