fresh-deploy-friction

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/run.sh

The script appears to be an explicit Docker development/deployment harness rather than malware. The primary security flaw is accidental disclosure of forwarded API keys through the status echo. Remove secret values from the diagnostic output, for example by printing only variable names or a redacted marker. Treat the Dockerfile/image and any executed commands as trusted inputs because they receive forwarded credentials and repository contents.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 20, 2026, 08:53 PM
Package URL
pkg:socket/skills-sh/a-canary%2Farc-skills%2Ffresh-deploy-friction%2F@dda0874c5c6b73d2422ccf2d47ce4e8629f1d50db3064dc1c089ac7254e6ffc4
Security Audit — socket — fresh-deploy-friction