docebo

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's overall purpose is coherent, and the CLI comes from an official npm package rather than an obviously malicious source. However, all authentication, connection management, and action execution are funneled through Membrane instead of direct Docebo APIs, creating a third-party credential and data mediation layer; combined with mutable `@latest` installs and remote action generation, this makes the skill higher risk than a direct vendor integration.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
May 2, 2026, 07:29 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdocebo%2F@a7c11046d5113ec87ae8ebd46fb8f437074a22c1
Security Audit — socket — docebo