cf-proxy

Warn

Audited by Socket on May 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s actions mostly match its stated purpose, but its trust model is weak. It chains a third-party skill installer, a personal skill repo, and unrelated third-party proxy code, then uses credentials to perform real-world DNS/deployment actions. I see no clear credential-stealing or hidden exfiltration, so this is not confirmed malware, but it is a high-risk infrastructure skill with significant supply-chain and transitive-trust concerns.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
May 3, 2026, 06:25 PM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fcf-proxy%2F@94f8ff11d0ae1eba11239c3fedbc2577c3212c30