deepl
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's capabilities mostly match its stated DeepL-integration purpose, and the install path is a low-risk official npm package rather than a raw downloader. However, the core data flow is not direct to DeepL: authentication and API requests are mediated by Membrane, including a generic proxy feature. That intermediary architecture is documented and vendor-consistent, so this is not confirmed malware, but it materially expands trust and exposes user data/API activity to a third-party platform beyond DeepL itself.
Confidence: 89%Severity: 52%
Audit Metadata