databricks

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its Databricks-management purpose, and the CLI install source is official npm rather than a suspicious download. However, all authentication and API activity are funneled through Membrane as an intermediary, expanding trust and data exposure beyond direct Databricks APIs; combined with unpinned CLI installation and the ability to trigger impactful workspace actions, this makes the skill medium-risk rather than benign.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 03:21 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdatabricks%2F@e6d9bb7af51c207128d39e197a1b5f82cf9e0664