alibaba-cloud

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent as an Alibaba Cloud integration, and the CLI source appears legitimately tied to Membrane, so this is not strong malware evidence. However, it routes authentication and API traffic through Membrane rather than direct Alibaba tooling, creating meaningful third-party credential and data-flow risk, with broad cloud-management capability and unpinned latest CLI install.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:05 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Falibaba-cloud%2F@618d61cd8858bf83905d844ea4ed711594efa978