docusign

Warn

Audited by Socket on Sep 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose matches DocuSign operations, and the installer is from an official npm package rather than a raw downloader. However, the actual data flow is brokered through Membrane, a third-party CLI/service that handles authentication and API requests instead of using direct DocuSign APIs; combined with an unpinned global install, this creates medium security risk and a notable credential/data-routing concern.

Confidence: 89%Severity: 61%
Audit Metadata
Analyzed At
Sep 29, 2026, 03:30 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdocusign%2F@3d644526b700b99b7dc021cb4213757c9a6997ffe67322a3f69b5687005cf76f
Security Audit — socket — docusign