vtex

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities generally align, and the CLI comes from an official npm package rather than an unknown binary. However, it routes authentication and VTEX operations through Membrane as an intermediary, adding a third-party trust and data-flow layer beyond official VTEX APIs, and it uses unpinned `@latest` installs. This is not confirmed malware, but it carries meaningful security and privacy risk for enterprise commerce data.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
May 4, 2026, 11:41 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fvtex%2F@231cafa6cff858b17ea182eec5af93990b543722
Security Audit — socket — vtex