doppler

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core function is coherent with Doppler management, and the installer source is legitimate npm-based tooling from the same vendor ecosystem. However, the data flow is not direct Doppler integration: all authentication and API traffic are routed through Membrane, adding a third-party credential/data mediation layer that is broader than a typical service-specific skill. This is not confirmed malware, but it is a moderate security risk due to proxy-based access to secrets management data.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 23, 2026, 12:55 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdoppler%2F@d5f7a647fda1bb1bd4f34f469385f36bbfd8eb92