deputy

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose matches its Deputy-management capabilities, and the CLI comes from an official npm package, so this is not clearly malicious. However, all authentication and data access are routed through Membrane instead of Deputy’s official API, and the skill enables dynamic action generation plus potentially impactful workforce changes. That makes the trust and data-flow footprint broader than a simple direct Deputy client, with moderate security risk but limited evidence of malware.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
May 1, 2026, 10:24 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdeputy%2F@b15eb6deef07f72ac593b0c8b84440608f1235ce
Security Audit — socket — deputy