kestra-ops

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The main kestractl-based operational behavior is coherent and uses official Kestra tooling, but the skill expands trust by instructing installation of another skill through a third-party skills CLI, and the named migration skill could not be verified from the same repo listing. No clear exfiltration or malicious endpoint routing was found, but the transitive install path and token-handling examples raise medium security concerns.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 05:51 PM
Package URL
pkg:socket/skills-sh/kestra-io%2Fagent-skills%2Fkestra-ops%2F@cce444e17f03bc36f0d719a6e4816e7ff9bff10dc19e8ffa3c06f90fde58ca09
Security Audit — socket — kestra-ops