google-dialogflow

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s behavior is coherent with a Membrane-managed Dialogflow workflow, and its install source is a normal npm package, not a hidden payload. However, it materially changes the trust boundary by routing Google Dialogflow access, authentication handling, and action execution through Membrane’s intermediary service instead of official Google APIs, while also using mutable `@latest` installs. This is better classified as a medium-risk third-party gateway pattern than malware.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 3, 2026, 12:28 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgoogle-dialogflow%2F@00b23420056231a7c764d9c706b9c22c550c5193
Security Audit — socket — google-dialogflow