NYC

cloudinary

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is an instructional document for using Cloudinary APIs. Its requested credentials (cloud name, API key, API secret) and demonstrated flows are consistent with the stated purpose. No malicious code, credential-harvesting redirects, or third-party intermediaries are present. The primary security considerations are standard: protect CLOUDINARY_API_SECRET, be careful with delete commands, and avoid sending sensitive secrets to client-side contexts (use unsigned presets where appropriate).

Confidence: 75%Severity: 15%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:31 PM
Package URL
pkg:socket/skills-sh/vm0-ai%2Fvm0-skills%2Fcloudinary%2F@6b50283c4398c9e930e1b1247012e1b976195b8f