bunnycdn

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities largely match its BunnyCDN-management purpose and the CLI install source appears official, so this is not overtly malicious. The main concern is data-flow integrity and trust expansion: BunnyCDN authentication and operations are routed through Membrane's hosted connection/action layer instead of directly to Bunny, plus the skill enables impactful administrative actions. Overall this is a coherent but medium-risk third-party integration skill, not confirmed malware.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 4, 2026, 11:39 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbunnycdn%2F@caaf5234d37b1bfa4cac8a33c65b19754db1d4e8
Security Audit — socket — bunnycdn