datarobot

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated DataRobot integration purpose, and the CLI install path is consistent with the publisher’s official npm distribution. The main concern is data-flow integrity: DataRobot access is mediated through Membrane rather than direct official DataRobot endpoints, so credentials and API traffic are entrusted to a third-party intermediary. This is not confirmed malware, but it is a medium-risk integration pattern with external-action capability.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Mar 16, 2026, 03:03 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdatarobot%2F@1b23004f63f3b35c10c8ba0f226510c6c007408f