deepseek

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, but it routes DeepSeek access, authentication, and action execution through Membrane rather than the official DeepSeek API. Installation source is relatively trustworthy via npm and official docs, so this is not confirmed malware; however, third-party credential handling, request logging/data retention, and dynamic action generation make the data flow and trust model broader than a simple DeepSeek integration.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Apr 29, 2026, 03:19 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdeepseek%2F@71501dd208c3f358df3e21057b1d24f7acb23d35
Security Audit — socket — deepseek