wealthbox

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities are broadly aligned with its Wealthbox integration purpose, and its install path uses an official npm package rather than an unverifiable binary. However, all authentication and data access are routed through Membrane instead of directly to Wealthbox, creating third-party credential/data exposure and moderate trust expansion; this is coherent with the product model but increases security risk versus a direct official API integration.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 01:43 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwealthbox%2F@e8f281dbfbf8b99cdd08fcb4d9efab04979e045a
Security Audit — socket — wealthbox