woodpeckerco

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the overall footprint mostly fits a Membrane-based Woodpecker integration, and the CLI comes from an official npm package under the same vendor scope. However, the skill is not a direct Woodpecker integration; it intermediates authentication and data through Membrane, uses mutable `@latest`, stores local CLI secrets, and includes an incorrect 'official docs' link to Woodpecker CI. These inconsistencies and the third-party credential/data routing make it higher-risk than a normal first-party API skill, but not clearly malicious.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
May 2, 2026, 12:03 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwoodpeckerco%2F@91ee557276dcce08e7bf7a3856aafbf8ca440664
Security Audit — socket — woodpeckerco