neo-azure-pipelines

Warn

Audited by Socket on Jun 15, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/deploy/deploy-iis.yml

This YAML wrapper is a conventional IIS deployment pipeline and contains no overt malicious code. The main security concerns are indirect: it deploys potentially untrusted artifact contents into parameter-controlled directories on a privileged server and delegates all critical side effects (IIS config changes, file writes/copy/backup/rollback, web.config edits) to external templates whose behavior is not visible here. Ensure strong controls over artifact provenance and strict validation/authorization for parameters such as websitePhysicalPath and backupPath in the referenced templates. Overall risk is moderate due to deployment impact, but malware likelihood in this fragment is low.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 15, 2026, 01:35 AM
Package URL
pkg:socket/skills-sh/Benknightdark%2Fneo-skills%2Fneo-azure-pipelines%2F@43215c090c727421a9fd60ba0cb20e0aa73c62e29db01c874a68e2ee00f3ebfd
Security Audit — socket — neo-azure-pipelines