cloudflare-registrar
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose and requested Cloudflare credentials are broadly coherent with registrar operations, and the API paths match official Cloudflare endpoints. However, it routes credentials and requests through an external CLI/MCP layer (`mcporter` -> `cloudflare-openclaw`) whose server ownership and data path are not verified in the skill, and it uses unpinned `npx` execution. The billable registration capability is high-impact but partially mitigated by the explicit confirmation guardrail.
Confidence: 85%Severity: 64%
Audit Metadata