openchoreo-platform-engineer

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
resources/workflow-templates/containerfile-build.yaml

This module is not overtly malicious; it primarily functions as a privileged container build-and-package step. The primary security concerns are structural: (1) privileged execution, (2) build-time execution of Dockerfile logic via podman build using parameters that shape Dockerfile behavior (build-env/build-args) and select filesystem paths for the Dockerfile/context, and (3) shell-driven command construction with limited quoting/escaping, making upstream parameter trust and validation critical. Integrity risks also exist due to unpinned tool image tags used to run jq and Podman runner utilities.

Confidence: 60%Severity: 67%
Audit Metadata
Analyzed At
May 18, 2026, 09:12 AM
Package URL
pkg:socket/skills-sh/openchoreo%2Fskills%2Fopenchoreo-platform-engineer%2F@d10ecfe23c09cea04b959d9c1ba2a258467bef4c
Security Audit — socket — openchoreo-platform-engineer