gcp

Warn

Audited by Socket on Sep 11, 2026

3 alerts found:

Securityx2Anomaly
SecurityMEDIUM
evals/files/iam-policy.yaml

No malicious code is present because this is an IAM policy and contextual configuration, not executable software. The configuration presents high security risk due to excessive contractor owner access, broad editor access for a CI identity backed by an old static key, and storage access granted to all authenticated users. The contractor restriction cannot be guaranteed by this binding alone; an appropriate deny policy and least-privilege redesign are required.

Confidence: 98%Severity: 88%
SecurityMEDIUM
evals/files/cloudsql-instance.yaml

No malicious behavior or obfuscation is present. The configuration is not production-safe as shown because the database is publicly reachable from any IPv4 address and does not require SSL. Restrict authorized networks, enforce TLS, evaluate deletion protection and point-in-time recovery, and inspect Cloud Logging separately for the reported checkout-api errors.

Confidence: 99%Severity: 88%
AnomalyLOW
evals/files/cloudrun-service.yaml

The manifest contains no direct evidence of malicious behavior. It has supply-chain and exposure risks: the container image is pinned only by the mutable latest tag, public ingress is enabled, and a potentially broad default service account is attached. Use an immutable image digest, a dedicated least-privilege service account, and verify authentication and authorization controls. Assessment is limited because the referenced container image is not included.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Sep 11, 2026, 03:16 PM
Package URL
pkg:socket/skills-sh/lynricsy%2Fhyperskills%2Fgcp%2F@4a4400c9e81a61b537f9229e6a0069fc4a2747be19be8264522636203cc91939
Security Audit — socket — gcp