backup-disaster-recovery

Warn

Audited by Socket on Sep 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/backup-and-restore-script.md

No clear malicious behavior or intentional backdoor is present. The main security concern is that database contents and Kubernetes Secrets are uploaded to S3, making bucket permissions and encryption critical. Restore and cleanup operations are high impact, while several implementation defects can cause failures or unsafe behavior. Review S3 access controls, encryption, input validation, restore isolation, and the cleanup implementation before production use.

Confidence: 98%Severity: 55%
AnomalyLOW
references/disaster-recovery-plan-template.md

The fragment is a legitimate disaster-recovery Kubernetes manifest and contains no evident malware or intentional malicious behavior. It does contain a significant credential-handling weakness: AWS credentials and a password are hardcoded in the manifest, and the placeholder password is insecure. Use an external secret manager or securely provisioned Kubernetes Secret, rotate any exposed credentials, and enforce encryption at rest and least-privilege access.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:46 AM
Package URL
pkg:socket/skills-sh/aj-geddes%2Fuseful-ai-prompts%2Fbackup-disaster-recovery%2F@a711a78772cac1a26b99caa8d19685dac93bde14b27292369da9c6d47f604f82
Security Audit — socket — backup-disaster-recovery