wrapper-tf

Warn

Audited by Socket on Sep 1, 2026

1 alert found:

Security
SecurityMEDIUM
evals/cases/bad-cdtf-encryption-exposure/NOTES.md

No evidence of supply-chain malware or intentional obfuscation is present in the provided content; it is a fixture-like description. However, it indicates extremely high security risk if accurate: a Terraform output would expose the Aurora master password by not marking it sensitive=true, and multiple encryption/network hardening controls are described as disabled or missing (Aurora encryption at rest, ElastiCache encryption in transit, ALB HTTPS redirect with plaintext HTTP, and absence of WAF attachment), alongside public EKS control-plane exposure in prod. Overall, treat this as a critical secret-disclosure and insecure-transport/increased-exposure configuration scenario requiring immediate remediation and verification in the actual Terraform code.

Confidence: 68%Severity: 93%
Audit Metadata
Analyzed At
Sep 1, 2026, 06:48 AM
Package URL
pkg:socket/skills-sh/anmolnagpal%2Fdevops-skills%2Fwrapper-tf%2F@c2098bb426246003f34bf529163df9ff129526fb1ec1f2d78af9ad4ce64d19d8
Security Audit — socket — wrapper-tf