wufoo

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose is coherent, and the install path uses an official npm package rather than a raw downloader, so this is not overtly malicious. However, it proxies Wufoo access and credential handling through Membrane instead of using Wufoo's official API directly, creating a meaningful third-party trust and data-flow risk; overall this is a proportionate but intermediary-heavy integration.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 09:11 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwufoo%2F@000b0cd1af84dd179a1f29a31b4597307755a22c
Security Audit — socket — wufoo