kestra-ops
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The main kestractl-based operational behavior is coherent and uses official Kestra tooling, but the skill expands trust by instructing installation of another skill through a third-party skills CLI, and the named migration skill could not be verified from the same repo listing. No clear exfiltration or malicious endpoint routing was found, but the transitive install path and token-handling examples raise medium security concerns.
Confidence: 88%Severity: 62%
Audit Metadata