linkerd-expert

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
references/CORE_CONCEPTS.md

The fragment is Linkerd operational documentation, not malicious package code. It contains a notable supply-chain risk because it recommends downloading and executing a remote installer with curl | sh, plus insecure example practices including unencrypted certificate keys, --insecure certificate generation, permissive unauthenticated authorization, ambiguous duplicate YAML keys, and full-rate traffic tracing. These should be reviewed and hardened before production use. No malware, credential theft, backdoor, obfuscation, or destructive behavior is evident in the provided content.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 19, 2026, 06:42 PM
Package URL
pkg:socket/skills-sh/personamanagmentlayer%2Fpcl%2Flinkerd-expert%2F@b58df0ae553cfd5496841b5b18620c2c0763e76252786f7024e4805afbbdf454
Security Audit — socket — linkerd-expert