cluster-agent-swarm

Warn

Audited by Socket on Apr 10, 2026

3 alerts found:

Anomalyx3
AnomalyLOW
skills/orchestrator/SKILL.md

SUSPICIOUS: mostly coherent platform-orchestration behavior using official tools and official PagerDuty API, with no clear malicious exfiltration or deceptive installer. However, the skill's footprint exceeds pure coordination by autonomously running scripts, committing to git, creating PRs, and escalating incidents, so the scope is moderately risky and only partially aligned with the stated role.

Confidence: 83%Severity: 56%
AnomalyLOW
skills/gitops/SKILL.md

SUSPICIOUS: The skill is broadly aligned with a GitOps operator role and routes data to official services, so it does not show clear malware or credential-theft behavior. However, it enables high-impact autonomous real-world actions across clusters, Git remotes, cloud secret stores, and PagerDuty, with referenced helper scripts not provided; this makes it medium/high security risk despite coherent purpose.

Confidence: 89%Severity: 66%
AnomalyLOW
skills/security/SKILL.md

SUSPICIOUS: the skill is largely coherent with a Kubernetes/OpenShift security specialist role and uses official-looking service endpoints, but it is operationally powerful. Its scope includes live secret changes, cloud role assignments, SCC/RBAC modifications, PagerDuty escalation, helper-script execution, and automatic git commits, which is broader and riskier than a passive audit guide.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Apr 10, 2026, 11:33 AM
Package URL
pkg:socket/skills-sh/kcns008%2Fcluster-agent-swarm-skills%2Fcluster-agent-swarm%2F@377ea215741a61cb28660c6a8dc1452df1a67279