onestack

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the deployment capability matches the stated purpose and the Dokploy CLI appears official, but the default data flow is to a self-hosted Dokploy instance on a raw IP over HTTP, which is disproportionate for token-based control-plane access. The main risk is insecure transport and credential exposure, not clear malware or deception.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Apr 28, 2026, 08:26 AM
Package URL
pkg:socket/skills-sh/gabia%2Fonestack.skill%2Fonestack%2F@b7398ed3abd40a31853274de7d98f625a03863ec