deepl

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s DeepL capabilities are mostly aligned with its stated purpose, and the CLI install path is official npm-based rather than an overt malware pattern. However, the core data flow is not direct DeepL integration: authentication, credentials, and user content are routed through Membrane’s third-party service, which is a meaningful trust expansion beyond a normal direct API skill. Combined with unpinned `@latest` install and remote action generation, this is better classified as suspicious than benign, though not malicious.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
May 4, 2026, 06:04 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdeepl%2F@f767e92e7f2e26cccafa79dc7002713ce4ec6f84
Security Audit — socket — deepl