sonarcloud

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities are mostly coherent, and the CLI comes from a normal npm package source rather than a suspicious installer. However, all SonarCloud access and auth are funneled through Membrane instead of official SonarCloud APIs, introducing a third-party credential/data mediation layer that is materially riskier than a direct integration.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 06:14 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsonarcloud%2F@e9ff3bfa9e25469562fddd77df13a4bf8efa9692
Security Audit — socket — sonarcloud