paddle
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's stated purpose and commands are mostly coherent, and the CLI install source appears legitimate and same-vendor. The main risk is architectural: Paddle access and authentication are routed through Membrane as an intermediary proxy rather than directly to official Paddle APIs, creating moderate credential and data-flow trust concerns but not clear malware behavior.
Confidence: 84%Severity: 52%
Audit Metadata