deepl

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is not overt malware, but its actual footprint is broader than a normal DeepL integration. It installs a third-party CLI, forwards authentication and API activity through Membrane-operated infrastructure instead of DeepL directly, and uses an unpinned global package install. This is a coherent integration pattern for Membrane, but not proportionate to a plain 'DeepL' skill without clearly foregrounding the intermediary trust boundary.

Confidence: 87%Severity: 63%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdeepl%2F@86ab58f28b1106e9cbcbdc58eea16c0f42f45347b423221d45c266d1a618aa50
Security Audit — socket — deepl