cloudflare

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's stated purpose is plausible, but the actual deployment path appears to route code, auth, and optional OpenRouter credentials through a Vibes-managed intermediary rather than direct official Cloudflare API flows. That mismatch and the hidden deploy script make the skill medium-high risk, though there is not enough evidence here to call it confirmed malware.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Mar 29, 2026, 07:25 PM
Package URL
pkg:socket/skills-sh/popmechanic%2Fvibes-cli%2Fcloudflare%2F@fd1f1a55129a277cd57250364f2df5edde4eb7c7
Security Audit — socket — cloudflare