dripcel

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent and vendor-aligned, with an official npm CLI and a plausible purpose, so it does not look outright malicious. However, it routes Dripcel authentication and operations through Membrane instead of Drip's official direct API, forwards sensitive access to a third-party platform, uses an unpinned CLI install, and enables impactful messaging/account actions; this makes it medium risk rather than benign.

Confidence: 84%Severity: 54%
Audit Metadata
Analyzed At
Apr 29, 2026, 01:45 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdripcel%2F@7538af103f9a28fe7d1f0de514b290e1e444fe88
Security Audit — socket — dripcel