cumulus-infra
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities largely match its stated Kubernetes/Flux operations purpose, and it contains no direct malicious or exfiltration instructions. However, it depends on a custom unattended exec credential helper that streams kubeconfig/client certs from a secret store, with no provenance or verification details in the skill; that makes trust and credential handling weaker than a purely benign documentation skill.
Confidence: 84%Severity: 61%
Audit Metadata