deploy-verify
Warn
Audited by Socket on Jul 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core workflow is mostly aligned with post-deploy verification and uses largely official service paths, so it is not strongly indicative of malware. Risk is elevated by broad `.env` scanning, multi-service scope, SQL/log access, unpinned `npx` execution, and autonomous rollback/hotfix guidance; the unused Firecrawl claim adds inconsistency.
Confidence: 85%Severity: 62%
Audit Metadata