duffel

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities mostly align, and the CLI install path appears to be official npm distribution from the same vendor. However, the skill routes authenticated Duffel activity through Membrane's intermediary service instead of directly to Duffel, creating a third-party credential and data handling dependency that is broader than a direct API integration.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 08:51 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fduffel%2F@3f4b4eebf56de55fa3719f0c67f9eed9d020a05f