cloudflare

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Anomaly
AnomalyLOW
references/sandbox/patterns.md

No definitive malware behavior is shown in the provided fragment. However, the snippet uses sandbox.exec to run git clone with a GitHub token embedded directly in the clone URL, creating a significant risk of credential leakage through command/log/trace visibility. The fragment is incomplete, so further suspicious behavior cannot be ruled out, but the strongest actionable finding here is insecure secret handling in an executed command string.

Confidence: 45%Severity: 62%
Audit Metadata
Analyzed At
Jul 21, 2026, 12:29 AM
Package URL
pkg:socket/skills-sh/dallay%2Fopencode-docker%2Fcloudflare%2F@55ab1b19a07495a33eb995426d97482ff677eee10fa5e47f83f48f3f19c4de4c
Security Audit — socket — cloudflare