cloud-foundry
Warn
Audited by Socket on Apr 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose and capabilities mostly align, and the CLI install path is a standard same-publisher npm package rather than a hidden payload. However, the core data flow routes Cloud Foundry access and authentication through Membrane’s third-party proxy/service instead of direct Cloud Foundry APIs, creating a meaningful trust-boundary expansion that is not strictly necessary for the stated integration.
Confidence: 88%Severity: 56%
Audit Metadata