deepseek

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, but it routes DeepSeek access, authentication, and action execution through Membrane rather than the official DeepSeek API. Installation source is relatively trustworthy via npm and official docs, so this is not confirmed malware; however, third-party credential handling, request logging/data retention, and dynamic action generation make the data flow and trust model broader than a simple DeepSeek integration.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Apr 22, 2026, 06:54 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdeepseek%2F@9a7c032f0036e814aae2099ccbb7de1a702a41ae