devops-engineer

Warn

Audited by Socket on Jul 9, 2026

1 alert found:

Anomaly
AnomalyLOW
references/platform-engineering.md

No direct evidence of overt malware/backdoors or data exfiltration is present in this fragment. The main supply-chain/security concerns are trust and validation gaps: remote templates/workflows/modules are referenced without visible pinning, ArgoCD auto-prunes/self-heals (high impact of compromised inputs), FastAPI derives a provisioning template name from request.language without an allowlist, and FastAPI/CLI interpolate user-controlled strings into URLs/payloads and kubectl arguments. Additionally, a credential-like integration key appears hardcoded in catalog annotations. Overall this is more of a platform trust-risk than confirmed malicious code.

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Jul 9, 2026, 10:07 PM
Package URL
pkg:socket/skills-sh/Codeblackbyshazzy%2Fopencode-skills%2Fdevops-engineer%2F@79d9d445c44d3def376bb048e9fde7a7ab36cfbb14e0b881d27bc7ddc128a371