sonarcloud

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, and the CLI install path is consistent with the publisher, so this is not obviously malicious. However, the integration routes authentication and API traffic through Membrane rather than directly to SonarCloud, creating a meaningful intermediary trust and data-flow risk; combined with execution of a vendor CLI and an unpinned `npx @latest` example, this makes the skill medium risk rather than benign.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Mar 13, 2026, 08:21 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsonarcloud%2F@36d05321a81e4261bd53f1ba43ca17f495acecf3