kubernetes-specialist

Warn

Audited by Socket on Aug 2, 2026

1 alert found:

Anomaly
AnomalyLOW
references/workloads.md

No explicit malicious payloads are evident in the provided Kubernetes YAML itself; it primarily orchestrates migrations and backups using secrets/config and scheduled execution. However, the setup presents notable security and supply-chain risk signals: unpinned/mutable container image tags (e.g., :latest), shell-based command execution patterns, and a possible hostPath exposure of /proc and /sys that would increase blast radius if images/scripts are compromised. Validate and harden by pinning images by digest, verifying image provenance/signatures, and auditing the referenced migration/backup artifacts and RBAC permissions for the service accounts.

Confidence: 55%Severity: 60%
Audit Metadata
Analyzed At
Aug 2, 2026, 08:52 PM
Package URL
pkg:socket/skills-sh/Krypton-Kr36%2Fclaude-code-skills%2Fkubernetes-specialist%2F@61bc4253606296cd0067e14ab444f13fc4a65a50ac3ee69ec5f57ae5b5dde2ed
Security Audit — socket — kubernetes-specialist