cloudflare-worker-builder

Fail

Audited by Socket on Feb 22, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Natural language instruction to download and install from URL detected All findings: [CRITICAL] command_injection: Natural language instruction to download and install from URL detected (CI009) [AITech 9.1.4] [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] BENIGN: The code fragment is a legitimate scaffolding/deployment workflow for Cloudflare Workers. It describes steps and configuration patterns consistent with its stated purpose and does not introduce credential access, suspicious network behavior, or hidden payloads. LLM verification: The provided skill is an instructional scaffold for Cloudflare Workers. It contains no embedded malware or explicit data-exfiltration/backdoor code. The main security concerns are operational: unpinned npm installs (supply-chain risk) and guidance that instructs users to run external CLIs which will fetch and execute third-party code and use their Cloudflare credentials during deploy. Recommend pinning dependency versions, auditing installed packages, documenting secure credential handling, and

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 22, 2026, 08:42 PM
Package URL
pkg:socket/skills-sh/jezweb%2Fclaude-skills%2Fcloudflare-worker-builder%2F@20a2cfd4813ec710ff65320488f3e6c8898cf0f7