cloudbase

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core CloudBase guidance is broadly aligned with its stated purpose, and the main MCP package appears official. Risk comes from unpinned `npx` execution, reliance on third-party `mcporter`, and especially the instruction to install additional skills via the external `skills` CLI, which extends the agent’s trust boundary. This looks more like a legitimate but high-trust operational skill than malware.

Confidence: 88%Severity: 61%
Audit Metadata
Analyzed At
May 1, 2026, 03:32 AM
Package URL
pkg:socket/skills-sh/tencentcloudbase%2Fcloudbase-skills%2Fcloudbase%2F@0a2b23089ab5b743429e116bb5748012a3914895