debugbear

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose generally matches its capabilities, and the CLI source appears to be the publisher's official npm package, so this is not strong evidence of malware. However, the skill routes DebugBear authentication and API traffic through Membrane rather than DebugBear's direct official API path, creating meaningful credential-forwarding and intermediary data-flow risk. Overall this is a coherent integration skill with medium security risk due to third-party mediation and mutable CLI installs, not a clearly malicious one.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Apr 28, 2026, 08:15 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdebugbear%2F@125df47b7a381156fff25ec7f45746d9325dd300
Security Audit — socket — debugbear