cloudbase
Warn
Audited by Socket on May 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core CloudBase guidance is broadly aligned with its stated purpose, and the main MCP package appears official. Risk comes from unpinned `npx` execution, reliance on third-party `mcporter`, and especially the instruction to install additional skills via the external `skills` CLI, which extends the agent’s trust boundary. This looks more like a legitimate but high-trust operational skill than malware.
Confidence: 88%Severity: 61%
Audit Metadata