cloudflare-r2
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's basic function is coherent, and the CLI install source is relatively legitimate, but the core design routes Cloudflare R2 access through Membrane as a third-party intermediary and requires a separate Membrane account. That data-flow mismatch and credential delegation are disproportionate to a straightforward Cloudflare R2 skill, making this higher-risk than a direct official integration.
Confidence: 88%Severity: 71%
Audit Metadata