cloud-foundry

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent and uses an official npm-distributed Membrane CLI, but it routes Cloud Foundry authentication and API traffic through Membrane as an intermediary service. That third-party credential and data mediation is disclosed and plausibly part of the product, so this is not confirmed malware, but it creates medium security risk versus direct Cloud Foundry access.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:32 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcloud-foundry%2F@28d28bda7ff57ad58f985fc14f5b808a25222982
Security Audit — socket — cloud-foundry