upcloud

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent for a Membrane-based UpCloud integration, and the CLI source appears legitimate, but the actual data flow routes credentials and API traffic through Membrane rather than directly to UpCloud. That intermediary design is disclosed and may be product-intended, so this is not confirmed malware, but it materially raises trust and security risk for a cloud-management skill.

Confidence: 88%Severity: 61%
Audit Metadata
Analyzed At
Apr 2, 2026, 07:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fupcloud%2F@64daa7e85771be26a6e4f8552e11f7d96978f5b7