dropbox-business

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities match its stated Dropbox Business purpose, and installation is via an official npm package rather than an unverifiable binary. The main concern is data-flow integrity: Dropbox access is brokered through Membrane’s service and proxy, so Dropbox data and auth operations transit a third-party intermediary instead of going directly to Dropbox APIs. That makes the skill coherent but medium-risk rather than benign.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 02:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdropbox-business%2F@08ce012b17855eec34d1cf237c33f94f20d7ae1b