cloudentity

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent and uses an official npm-distributed CLI from the apparent same vendor, so there is no strong malware signal. However, it routes Cloudentity authentication and data operations through Membrane rather than directly to official Cloudentity APIs, creating a third-party credential and data-flow trust dependency; combined with unpinned latest CLI execution, this makes the skill medium risk rather than benign.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 22, 2026, 07:42 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcloudentity%2F@db233dc4705a83ce118a575fc7be7ca6a2fb308b