vosfactures

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches its capabilities, and the CLI comes from an official npm package, so this is not overtly malicious. However, it routes authentication and all Vosfactures operations through Membrane as an intermediary, uses an unpinned third-party CLI, and enables live business-data actions via that platform; this makes it a medium-risk integration rather than a benign direct API helper.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 03:22 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fvosfactures%2F@e4721dd58997a6e8a83ab1f0e313066bf58cf0dd
Security Audit — socket — vosfactures