openshift-docs

Warn

Audited by Socket on Jul 28, 2026

1 alert found:

Security
SecurityMEDIUM
docs/4.22/authentication/managing-oauth-access-tokens.md

No embedded malware, obfuscation, or data-exfiltration behavior is present in this fragment; it is a static administrative procedure for creating a ClusterRoleBinding. However, it explicitly describes a security-critical authorization change by binding the system:unauthenticated group to a chosen ClusterRole, which can significantly expand unauthenticated capabilities if misused. This should be treated as a high-governance, high-risk configuration action requiring strict validation of the referenced ClusterRole and deployment controls.

Confidence: 72%Severity: 78%
Audit Metadata
Analyzed At
Jul 28, 2026, 11:11 PM
Package URL
pkg:socket/skills-sh/openshift%2Fagentic-skills%2Fopenshift-docs%2F@0b4fbc596071e10e411a91f4c1e7e9d7d8b1b25e135a3d74b5b70191fb7892d9
Security Audit — socket — openshift-docs