kelly-devops

Warn

Audited by Socket on Aug 25, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/publish_airapp.mjs

No clear evidence of malware, backdoor behavior, or obfuscated/hidden execution in this module. However, the script is high-impact from a supply-chain/policy perspective because it recursively reads nearly all files under a local content directory (only lightly excluded) and uploads their contents to a remote Busabase service via publishAirApp using env-provided credentials. If the directory contains sensitive data or unexpected artifacts, this can cause unintended data exposure.

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Aug 25, 2026, 10:38 AM
Package URL
pkg:socket/skills-sh/mr-kelly%2Fskills%2Fkelly-devops%2F@641e788aa1a8336c4c86b80956f9933304d9e051dc77ab72a2b7a0eff494f830
Security Audit — socket — kelly-devops