superdocu

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is largely consistent with its stated purpose and uses an official npm-distributed CLI, but it routes Superdocu authentication and API traffic through Membrane rather than directly to Superdocu. That intermediary architecture and mutable CLI install create medium security risk, though there is not enough evidence of malware or overt credential theft.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 03:21 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsuperdocu%2F@688a4a6537b7db41d9259919eee551854fb85392
Security Audit — socket — superdocu