mcp-cloudflare

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly aligned with its Cloudflare admin/troubleshooting purpose and uses official Cloudflare MCP endpoints, but the container sandbox expands scope by enabling execution of arbitrary external repos and npm dependencies. Main risks are indirect prompt injection from fetched content and supply-chain exposure in sandbox workflows, not clear malware or credential theft.

Confidence: 91%Severity: 58%
Audit Metadata
Analyzed At
Sep 5, 2026, 04:34 AM
Package URL
pkg:socket/skills-sh/enuno%2Fclaude-command-and-control%2Fmcp-cloudflare%2F@9114a82a7720ae3dec32542a35d25875652728a42817f08ab4cad3217afde3b2
Security Audit — socket — mcp-cloudflare