oh-dear

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities generally match its stated Oh Dear! integration purpose, and the CLI install path is from the official npm registry rather than an unverified download. However, all authentication and API access are mediated through Membrane instead of going directly to Oh Dear!'s official API, which expands the trust boundary and creates third-party credential/data handling risk. This looks more like a legitimate but trust-heavy integration pattern than confirmed malicious behavior.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 07:46 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Foh-dear%2F@8f0bbdfc362cb77cddc4375fb396570af6b581fa
Security Audit — socket — oh-dear