cloudflare-api-shield

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, and the CLI comes from an official registry tied to the publisher, but it expands the trust boundary by routing Cloudflare authentication and API traffic through Membrane rather than directly to Cloudflare. This is not confirmed malware, but the third-party credential handling and proxy data flow create medium security risk for a Cloudflare-management skill.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcloudflare-api-shield%2F@00fdf7ed96ecd022996e0d49fc2e08dfeae280f2
Security Audit — socket — cloudflare-api-shield