docspring

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent as a Membrane-hosted DocSpring integration and does not show overt malware patterns, but it routes DocSpring access and credential lifecycle through a third-party intermediary instead of the official service directly. The npm install path is legitimate yet unpinned, so overall risk is moderate due to intermediary trust and mutable CLI execution rather than clear malicious behavior.

Confidence: 85%Severity: 57%
Audit Metadata
Analyzed At
May 1, 2026, 12:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdocspring%2F@b794225321c78b76fae008ed7b98d51d37390fb6