dux-soup

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly aligned with its stated Dux-Soup integration purpose and uses a publisher-consistent CLI from npm, but it routes authentication and API activity through Membrane as an intermediary rather than directly to Dux-Soup. That third-party credential handling and proxying make the data flow more expansive than a direct integration, while `@latest` installs add moderate supply-chain risk.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 08:36 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdux-soup%2F@83ab2594cc095c41ffe1973173aeb94350937e03