cloud-cost-management

Warn

Audited by Socket on Sep 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/terraform-cost-management-configuration.md

The fragment is readable Terraform infrastructure configuration with no apparent malware, exfiltration, credential theft, or backdoor behavior. Its main risk is potentially unintended financial impact from creating billable resources and committing to an ALL_UPFRONT 12-month Savings Plan. The resource names and some schema details should be validated before use, and the financial commitments should require explicit approval.

Confidence: 97%Severity: 55%
AnomalyLOW
references/azure-cost-management.md

The Azure management commands appear intended for legitimate cost monitoring and configuration. The curl-pipe-bash installer is a significant supply-chain and local system execution risk because arbitrary content returned by the remote URL is executed without verification. Review and verify the installer, download it first, inspect it, and use package signature or checksum validation before execution. No clear malware or data theft behavior is present in the supplied fragment itself.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:46 AM
Package URL
pkg:socket/skills-sh/aj-geddes%2Fuseful-ai-prompts%2Fcloud-cost-management%2F@87ceff6cf90fc6e261e5645ce0bdb27fdf315699570bcc8e7769c64b55888402
Security Audit — socket — cloud-cost-management