docraptor
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is internally coherent as a Membrane-hosted DocRaptor workflow, and its installer comes from an official registry path tied to the publisher. The main concern is data-flow integrity: DocRaptor operations and authentication are mediated through Membrane rather than going directly to DocRaptor, so user data and service access are exposed to an extra third party; combined with an unpinned CLI install, this makes the skill medium risk rather than benign.
Confidence: 86%Severity: 56%
Audit Metadata