azure-pipeline-architect

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/deploy/deploy-iis.yml

This YAML wrapper is a conventional IIS deployment pipeline and contains no overt malicious code. The main security concerns are indirect: it deploys potentially untrusted artifact contents into parameter-controlled directories on a privileged server and delegates all critical side effects (IIS config changes, file writes/copy/backup/rollback, web.config edits) to external templates whose behavior is not visible here. Ensure strong controls over artifact provenance and strict validation/authorization for parameters such as websitePhysicalPath and backupPath in the referenced templates. Overall risk is moderate due to deployment impact, but malware likelihood in this fragment is low.

Confidence: 62%Severity: 58%
Audit Metadata
Analyzed At
Apr 1, 2026, 04:47 AM
Package URL
pkg:socket/skills-sh/benknightdark%2Fneo-skills%2Fazure-pipeline-architect%2F@ce0da6e14dcf1929dbe92e5e5e8f8f30c69f5473
Security Audit — socket — azure-pipeline-architect