cloudfiles
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is not overtly malicious and uses an official npm-distributed CLI from the same publisher family, but it routes authentication and data access through Membrane rather than direct CloudFiles APIs, and the CloudFiles product/docs mismatch is a notable integrity issue. Overall risk is medium due to third-party credential/data mediation plus inconsistent service identity.
Confidence: 84%Severity: 56%
Audit Metadata