deepl

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated DeepL-integration purpose, and the install path is a low-risk official npm package rather than a raw downloader. However, the core data flow is not direct to DeepL: authentication and API requests are mediated by Membrane, including a generic proxy feature. That intermediary architecture is documented and vendor-consistent, so this is not confirmed malware, but it materially expands trust and exposes user data/API activity to a third-party platform beyond DeepL itself.

Confidence: 89%Severity: 52%
Audit Metadata
Analyzed At
Apr 22, 2026, 07:14 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdeepl%2F@be81704b02d81b02574d3c29c53bd2ba2f79e5b0