adobe-acrobat-sign

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely coherent with its stated Adobe Acrobat Sign integration purpose and uses an official npm-distributed Membrane CLI, so it does not look malicious. However, it routes authentication and Adobe data through Membrane rather than directly to Adobe APIs, creating meaningful third-party trust and credential/data handling risk; combined with the unpinned CLI install, this makes the skill moderately risky rather than benign.

Confidence: 83%Severity: 52%
Audit Metadata
Analyzed At
May 3, 2026, 01:03 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fadobe-acrobat-sign%2F@73b2459728f19bc8f9706585139822d6ac47e595