10duke

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated 10Duke integration purpose and uses an official-seeming Membrane CLI from npm, so it is not clearly malicious. The main concern is data-flow integrity: authentication and 10Duke access are brokered through Membrane, which stores and refreshes external credentials server-side, creating a third-party trust boundary beyond 10Duke itself. Combined with unpinned `@latest` installs, this makes the skill medium risk but not incompatible with its claimed purpose.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:08 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2F10duke%2F@f13095de531d11d0f788c42cdaa3a86dd9fec6da
Security Audit — socket — 10duke