doppler

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose is Doppler integration, but its real footprint is a Membrane-mediated integration that installs and authenticates a separate platform, then routes Doppler operations and potentially sensitive secret data through that intermediary. The install source is a legitimate npm package, so this is not strong malware evidence, but the third-party credential/data path and broad action-generation model make the skill higher-risk than a direct Doppler skill.

Confidence: 82%Severity: 64%
Audit Metadata
Analyzed At
Apr 30, 2026, 09:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdoppler%2F@67ad83ea196f7cd5d44f0c04dfb2edf75630fca0
Security Audit — socket — doppler