cali-ops-deploy-github-tailscale

Warn

Audited by Socket on Jul 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is coherent for CI/CD deployment, and its main external dependencies are official Tailscale/GitHub components. However, it contains meaningful security and trust issues: a curl|sh installer, broad local credential reuse by copying root Docker auth, non-immutable action pinning, and a significant technical inconsistency about Tailscale SSH on port 2222. These issues make the skill risky and error-prone, but not malicious.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Jul 18, 2026, 10:50 AM
Package URL
pkg:socket/skills-sh/calionauta%2Fagent-sync-public%2Fcali-ops-deploy-github-tailscale%2F@81735c9aec674071b95e1d3191b1e8dc5233ef0e77172e9fd53d0b503b3b23d9
Security Audit — socket — cali-ops-deploy-github-tailscale