deploy-verify

Warn

Audited by Socket on Jul 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core workflow is mostly aligned with post-deploy verification and uses largely official service paths, so it is not strongly indicative of malware. Risk is elevated by broad `.env` scanning, multi-service scope, SQL/log access, unpinned `npx` execution, and autonomous rollback/hotfix guidance; the unused Firecrawl claim adds inconsistency.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
Jul 24, 2026, 11:20 AM
Package URL
pkg:socket/skills-sh/kensaurus%2Fcursor-kenji%2Fdeploy-verify%2F@de3b3684f8d2667338f6e3f891d423cd3aab31b5aafbacced5e62c24ed871ace
Security Audit — socket — deploy-verify