debugbear

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is functionally coherent, but it shifts DebugBear authentication and API access to Membrane as an intermediary, so data and credentials do not flow directly to official DebugBear endpoints. The install source is official npm and same-vendor, which lowers malware concern, but mutable `@latest` execution plus third-party credential custody keep security risk in the medium range.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Apr 23, 2026, 10:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdebugbear%2F@94b88285742f5916acd614dc8bb4e30459448d6c