cloudflare-dns

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s DNS-management behavior matches its stated purpose, but it installs an unverifiable flarectl binary from a personal GitHub account rather than Cloudflare’s documented path, then forwards high-value Cloudflare credentials to that binary. This creates a severe supply-chain and credential-forwarding risk disproportionate to a routine DNS helper.

Confidence: 93%Severity: 90%
Audit Metadata
Analyzed At
Mar 28, 2026, 11:50 AM
Package URL
pkg:socket/skills-sh/OpenMinis%2FMinisSkills%2Fcloudflare-dns%2F@c052143333d7091a8c11bf0310173470f1750dfd