veracode

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The install path for the Membrane CLI appears consistent with Membrane's official distribution, so supply-chain risk is not the main issue. The core concern is data-flow integrity and scope: a Veracode skill should normally authenticate to and call Veracode directly, but this skill requires a separate Membrane account and sends all access through Membrane-managed connections and server-side credential handling. That intermediary architecture is disproportionate to the stated purpose and creates unnecessary third-party visibility into Veracode data and auth flows.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Apr 28, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fveracode%2F@149e0d26259b94e739861e52e031d6fce4ee43f1
Security Audit — socket — veracode