copper

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Copper integration skill presents a coherent and proportionate footprint for its stated purpose. It relies on Membrane-managed authentication, uses the official Membrane CLI from npm, and routes data through Membrane-controlled proxy endpoints to Copper. There are no evident red flags for credential leakage, hidden binaries, or excessive permissions. The security risk is low to moderate (0.25) with a small malware risk (0.05) given the reliance on trusted registries and server-side credential handling. Remain vigilant for any future additions that introduce direct credential exports or unverified binaries, and ensure Membrane's service/SLA for credential handling remains in place.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 10:01 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcopper%2F@397bc579ffea30ff14c5b01247e7521a6b4cc01a