k8s-service-path

Warn

Audited by Socket on Aug 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Purpose and actions are coherent for Kubernetes troubleshooting, and the skill text itself is read-only with no direct malicious behavior. The main issue is trust: it relies on a third-party `k8s-mcp` binary whose exact provenance is unclear, and that binary may operate with kubeconfig-backed cluster credentials, so this should be treated as suspicious high supply-chain risk rather than benign.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Aug 6, 2026, 09:48 AM
Package URL
pkg:socket/skills-sh/automateyournetwork%2Fnetclaw%2Fk8s-service-path%2F@37e097a44be13b7ce94883049872f69c5814891b6658ca8ae3f96604c2e71aad
Security Audit — socket — k8s-service-path