unity-cloud-build

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent as a Membrane-based Unity Cloud Build integration, and the CLI source appears vendor-aligned via npm rather than an unknown binary. However, it routes all access through Membrane instead of Unity directly, requires an extra third-party account, uses mutable `@latest`, and supports dynamic remote action creation/execution. This is better classified as medium risk due to intermediary credential/data handling and expanded trust boundaries, not confirmed malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 3, 2026, 05:33 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Funity-cloud-build%2F@e933ff515500884d436a602aa243f9c32591ecd1