mcloud-environments

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s capabilities match its stated purpose, and there is no clear exfiltration path, but it relies on an unverifiable `mcloud` CLI not confirmed by official docs and can perform destructive remote environment actions. Main concern is execution trust and binary provenance, not confirmed malware.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
May 8, 2026, 12:48 PM
Package URL
pkg:socket/skills-sh/medusajs%2Fmedusa-agent-skills%2Fmcloud-environments%2F@51708f0a1aaf0e27eeee52c059b4cf0ec66ba7d3