dynatrace-api

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent as a Dynatrace integration, and the Membrane CLI appears to be an official same-vendor tool from npm, not an obviously malicious payload. However, the core data flow is mediated through Membrane for authentication, credential refresh, and API proxying instead of direct Dynatrace endpoints, which creates a third-party trust boundary disproportionate to a plain Dynatrace API skill. Main risk is credential/data routing and broad proxy capability, not confirmed malware.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
Apr 29, 2026, 08:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdynatrace-api%2F@9f46cf9513802d3d1036d9f5d8e32900df27b41e
Security Audit — socket — dynatrace-api