deploying-tailscale-for-zero-trust-vpn

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The overall purpose is coherent for a Tailscale deployment guide, and most capabilities fit that purpose, but install trust is weakened by an official yet unpinned curl|sh path and especially by the separate Headscale binary download from a personal GitHub repo using a mutable latest URL without integrity checks. Credential use is proportionate, and there is no clear exfiltration or malicious redirection, but the third-party binary install and doc mismatches raise medium-high security risk.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Apr 12, 2026, 10:17 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fdeploying-tailscale-for-zero-trust-vpn%2F@30e2c33bed97b0dfb6d8675a0773fb2a0a3657f9