google-cloud

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities are broadly coherent, and the CLI comes from a normal npm source, but the integration routes Google Cloud authentication and operations through Membrane as a third-party intermediary rather than directly to official Google Cloud APIs. That makes the main concern data-flow integrity and delegated trust, not confirmed malware. Unpinned `@latest` installation and broad cloud-management scope add moderate risk.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 02:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgoogle-cloud%2F@39963f13287d727364e66f1192f5e922d62ad779