nextcloud

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, and the CLI comes from a plausible official npm source, but the integration routes authentication and Nextcloud data through Membrane rather than directly to Nextcloud. The main concern is third-party credential/data brokerage plus an inaccurate 'no local secrets' claim, not confirmed malware.

Confidence: 90%Severity: 56%
Audit Metadata
Analyzed At
Sep 19, 2026, 01:57 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnextcloud%2F@2ae9cdf135bf43512fbb916ce61e8df724062732c6ce684178d21d21dd4e5093
Security Audit — socket — nextcloud