document360

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent with its stated purpose and uses an official-looking npm package rather than a hidden installer, so it is not malware-like. However, it routes Document360 authentication and API traffic through Membrane as an intermediary and uses an unpinned CLI install, creating meaningful third-party trust and external-action risk that is higher than a direct official API integration.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
Apr 30, 2026, 11:08 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdocument360%2F@361414c9b400f9b5450d8f4e4db41d11f5e1eaf8