cloudflare-r2

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's basic function is coherent, and the CLI install source is relatively legitimate, but the core design routes Cloudflare R2 access through Membrane as a third-party intermediary and requires a separate Membrane account. That data-flow mismatch and credential delegation are disproportionate to a straightforward Cloudflare R2 skill, making this higher-risk than a direct official integration.

Confidence: 88%Severity: 71%
Audit Metadata
Analyzed At
Apr 29, 2026, 08:23 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcloudflare-r2%2F@2513605a2c3a306b3d220f3a9352b657ba141e44
Security Audit — socket — cloudflare-r2