upcloud

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the install source is coherent and official for Membrane, but the skill’s real behavior is to funnel UpCloud authentication and API access through Membrane as an intermediary. That makes the trust and data-flow footprint broader than a straightforward UpCloud integration and creates meaningful credential-forwarding and proxying risk without clear necessity.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Apr 29, 2026, 03:22 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fupcloud%2F@ffc2880ca456ae11310153f183c9902226608839
Security Audit — socket — upcloud