nextjs-on-cloudflare

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent with Next.js-on-Cloudflare guidance, and the upstream target is legitimately Cloudflare-owned, so this is not malware-like. But the skill's main behavior is to install and defer to another skill through a third-party CLI, creating a real transitive trust and supply-chain risk disproportionate to a simple guide skill.

Confidence: 91%Severity: 52%
Audit Metadata
Analyzed At
Sep 5, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/cloudflare%2Fskills%2Fnextjs-on-cloudflare%2F@8a6210c0c275c7a2c7a498375d28062cf46aefd480725b5e064be79aaa457172
Security Audit — socket — nextjs-on-cloudflare