Polaris Kubernetes Best Practices Validator

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated purpose is plausible, but the trust path is inconsistent. It presents Fairwinds Polaris while instructing installation from unrelated third-party skill registries, creating a transitive trust-chain risk. No clear credential theft or exfiltration is shown, so this is not confirmed malware, but it is a medium-high security risk due to provenance mismatch and third-party skill loading.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:38 AM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fpolaris-kubernetes-best-practices-validator%2F@eaba2be9c5eddd6352ed81647c54f20e40a275e4