google-cloud-translate

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent for a Membrane-based Google Cloud Translate wrapper, and the CLI install comes from an official npm package tied to the same vendor. The main concern is data-flow integrity: translation activity and authentication are routed through Membrane rather than directly to official Google Cloud Translate APIs, plus the CLI install is unpinned (`@latest`). This is not confirmed malware, but it introduces moderate third-party trust and supply-chain risk beyond what the title alone suggests.

Confidence: 87%Severity: 54%
Audit Metadata
Analyzed At
May 3, 2026, 07:38 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgoogle-cloud-translate%2F@707d9d55684b0420ef054953d41462d7594df6c5
Security Audit — socket — google-cloud-translate