devops-automator

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
references/github-actions-patterns.yaml

No clear malicious behavior is present in this workflow. The main security concerns are CI supply-chain and privilege-boundary weaknesses: mutable third-party action references, execution of pull-request-controlled code, and registry write permissions with image pushing not restricted to trusted branches. The staging kubeconfig handling also has correctness and secret-lifecycle issues. Pin actions to verified commit SHAs, prevent untrusted pull requests from receiving write-capable build behavior or pushing images, and persist or securely manage KUBECONFIG only where needed.

Confidence: 97%Severity: 68%
Audit Metadata
Analyzed At
Sep 17, 2026, 07:31 AM
Package URL
pkg:socket/skills-sh/curiositech%2Fsome_claude_skills%2Fdevops-automator%2F@847f5d74682d3528ba6585852673902376c32e4513e013a7f2f26863b6a26329
Security Audit — socket — devops-automator