google-cloud
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose and capabilities are broadly coherent, and the CLI comes from a normal npm source, but the integration routes Google Cloud authentication and operations through Membrane as a third-party intermediary rather than directly to official Google Cloud APIs. That makes the main concern data-flow integrity and delegated trust, not confirmed malware. Unpinned `@latest` installation and broad cloud-management scope add moderate risk.
Confidence: 86%Severity: 58%
Audit Metadata