vectera

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent as a Membrane-based Vectera integration and uses an official npm-distributed CLI, so it is not outright malicious. However, it introduces a meaningful trust shift: Vectera authentication, data access, and action execution are routed through Membrane rather than directly to Vectera, which is a nontrivial third-party intermediary for credentials and customer data.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 8, 2026, 10:51 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fvectera%2F@2a30030ce0aee6a77c6b9ace95619799a9978ad7
Security Audit — socket — vectera