mcp-cloudflare
Warn
Audited by Socket on Sep 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: mostly aligned with its Cloudflare admin/troubleshooting purpose and uses official Cloudflare MCP endpoints, but the container sandbox expands scope by enabling execution of arbitrary external repos and npm dependencies. Main risks are indirect prompt injection from fetched content and supply-chain exposure in sandbox workflows, not clear malware or credential theft.
Confidence: 91%Severity: 58%
Audit Metadata