cloudflare

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Security
SecurityMEDIUM
references/sandbox/patterns.md

No explicit obfuscated malware or backdoor strings are present, but the module contains many high-risk operations that allow arbitrary code execution, network fetch-and-execute (curl | sh), persistence to external buckets, and potential credential leakage (embedding env tokens into git clone). If this code is used as-is in production without strong isolation, validation, and least-privilege controls it can be abused for remote code execution, secret exfiltration, and persistence. Treat as potentially dangerous in operational contexts and apply strict mitigations before use.

Confidence: 80%Severity: 70%
Audit Metadata
Analyzed At
Mar 19, 2026, 07:50 PM
Package URL
pkg:socket/skills-sh/pedronauck%2Fskills%2Fcloudflare%2F@c02e91b1e3445dec3a8e3f044577931738aadd60