documentpro

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated purpose, and the CLI comes from an official npm package rather than an unverifiable binary. However, the integration is only possible by routing authentication and DocumentPro API traffic through Membrane as an intermediary, and the lack of official DocumentPro API documentation reduces transparency. This looks more like a legitimate but trust-heavy gateway pattern than outright malware.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 23, 2026, 02:02 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdocumentpro%2F@a0c3db1966eff11148f3bdf1e67eda26671a0f6f