qadeputy
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The install path is relatively normal and same-vendor-aligned with Membrane, but the skill has a notable purpose mismatch and routes authentication/data through Membrane instead of Deputy's native API flow. This looks more like a mislabeled third-party integration wrapper than outright malware, with medium security risk from intermediary credential/data handling and unpinned CLI install.
Confidence: 85%Severity: 56%
Audit Metadata