digital-ocean

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities largely match its stated DigitalOcean-management purpose and its CLI install path appears vendor-consistent via npm, so this is not overt malware. However, the actual data flow is materially broader than a direct DigitalOcean integration: credentials and API traffic are mediated by Membrane, a third-party service, and the skill enables live create/delete operations on cloud resources. That makes the skill coherent but medium risk, mainly due to third-party credential/data handling and operational impact.

Confidence: 89%Severity: 57%
Audit Metadata
Analyzed At
Apr 29, 2026, 03:21 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdigital-ocean%2F@1f94bf27b7927d85c66d56caeba902736f6e209f
Security Audit — socket — digital-ocean