docusign
Warn
Audited by Socket on Sep 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose matches DocuSign operations, and the installer is from an official npm package rather than a raw downloader. However, the actual data flow is brokered through Membrane, a third-party CLI/service that handles authentication and API requests instead of using direct DocuSign APIs; combined with an unpinned global install, this creates medium security risk and a notable credential/data-routing concern.
Confidence: 89%Severity: 61%
Audit Metadata