linkerd-expert
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
AnomalyAnomalyreferences/CORE_CONCEPTS.md
LOWAnomalyLOW
references/CORE_CONCEPTS.md
The fragment is Linkerd operational documentation, not malicious package code. It contains a notable supply-chain risk because it recommends downloading and executing a remote installer with curl | sh, plus insecure example practices including unencrypted certificate keys, --insecure certificate generation, permissive unauthenticated authorization, ambiguous duplicate YAML keys, and full-rate traffic tracing. These should be reviewed and hardened before production use. No malware, credential theft, backdoor, obfuscation, or destructive behavior is evident in the provided content.
Confidence: 98%Severity: 58%
Audit Metadata