cloud-weaver-teardown

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core teardown behavior is coherent with the stated purpose and the GitHub CLI usage is official, but the fallback download of teardown.py from a personal domain is a notable supply-chain concern. Destructive actions are proportionate and user-confirmed, so this is not confirmed malware, but the remote script trust gap raises the overall risk.

Confidence: 90%Severity: 62%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:37 AM
Package URL
pkg:socket/skills-sh/fagnerlopes%2Fcloud-weaver%2Fcloud-weaver-teardown%2F@62381337c2384f5adfbb4df88d712a1addc723c629626fa077fcd7d70cec624c
Security Audit — socket — cloud-weaver-teardown