dc-bank

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent with its stated purpose, but it routes financial authentication and data through Membrane rather than direct bank APIs and executes unpinned CLI code from npm. This looks more like a legitimate hosted integration than malware, yet the third-party intermediary model and financial-data scope create medium security risk.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 06:42 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdc-bank%2F@f2aefc7b16f29750704fdd864053b451ee912aca
Security Audit — socket — dc-bank