deployhq

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent with its stated DeployHQ-management purpose and uses an official npm-distributed CLI, so there is no strong evidence of malware. However, it routes DeployHQ access and credential handling through Membrane’s intermediary service rather than the official DeployHQ API directly, which creates meaningful third-party trust and data-flow risk, especially for sensitive deployment operations.

Confidence: 90%Severity: 57%
Audit Metadata
Analyzed At
Apr 24, 2026, 09:23 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdeployhq%2F@39c8ceee794a23382da791b16195548678dca338