cloud-weaver-offboard
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent and most actions are proportionate for offboarding, with no obvious credential exfiltration path or deceptive routing. The main issue is trust delegation to an unverified local plugin script that performs privileged cloud operations using fresh API credentials; that unverifiable dependency makes the skill medium-high risk despite otherwise legitimate purpose alignment.
Confidence: 86%Severity: 74%
Audit Metadata