otel-declarative-config

Fail

Audited by Socket on Sep 16, 2026

1 alert found:

Malware
MalwareHIGH
evals/files/hostile-config.yaml

The configuration is unsafe and contains clear command-execution behavior. Unsafe YAML deserialization can execute printenv and disclose environment variables, while shell expansion of the OTLP endpoint can download and execute remote code. It should not be loaded with an unsafe YAML loader or processed through shell expansion. The comment requesting upload is inert and does not itself cause exfiltration.

Confidence: 98%Severity: 97%
Audit Metadata
Analyzed At
Sep 16, 2026, 08:47 AM
Package URL
pkg:socket/skills-sh/ollygarden%2Fopentelemetry-agent-skills%2Fotel-declarative-config%2F@5310e4cb2a24da3ad21709bc4ab1fcc36e08cc440d1e0288026200ad20b86cb2
Security Audit — socket — otel-declarative-config