cloudfiles

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overtly malicious and uses an official npm-distributed CLI from the same publisher family, but it routes authentication and data access through Membrane rather than direct CloudFiles APIs, and the CloudFiles product/docs mismatch is a notable integrity issue. Overall risk is medium due to third-party credential/data mediation plus inconsistent service identity.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 09:56 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcloudfiles%2F@2281bca9cb82b6d02d44ad88b2b7ab7f49d8c898