duo-security

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose broadly matches Duo Security integration, and its CLI install source appears legitimate. However, the core data flow is through Membrane as an intermediary rather than direct Duo endpoints, creating a notable trust and data-routing concern; combined with proxy capabilities and unpinned `@latest` usage, this is medium risk rather than clearly benign.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 21, 2026, 04:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fduo-security%2F@dedc1bbd37d77e03e295dd57c4313b10305a9bf2