cloudbase

Warn

Audited by Socket on Mar 29, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/cloudbase-platform/SKILL.md

SUSPICIOUS. The skill’s stated CloudBase purpose matches its content, and CloudBase MCP itself appears to be an official same-org npm package. However, it instructs the agent to use an unrelated third-party CLI (`mcporter`) as the launcher for authenticated MCP operations, with mutable `@latest` installs. That is a proportionate but non-trivial supply-chain and credential-forwarding risk, not clear malware.

Confidence: 86%Severity: 58%
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core purpose is coherent for a CloudBase development guide, and the CloudBase MCP package appears official. But it recommends unpinned `npx` execution, installs another skill transitively, and relies on a third-party `mcporter` runner whose publisher is not CloudBase/Tencent; combined with unclear auth-flow claims, this creates medium supply-chain and credential-routing risk rather than confirmed malware.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Mar 29, 2026, 04:21 AM
Package URL
pkg:socket/skills-sh/ljunn%2Fjunli-cloudbase%2Fcloudbase%2F@a38b41216788844af176e6a6134869b1c81f75e3