pulumi

Warn

Audited by Socket on Sep 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/auto-review-stacks.md

The fragment is ordinary review-stack documentation and contains no clear malicious payload. If deployed as shown, it presents a medium security concern because Pulumi executes pull-request-controlled infrastructure code in a workflow that supplies a Pulumi access token. Add explicit trust and approval controls, restrict secret-bearing runs, and limit cloud/Pulumi permissions. The code itself is not obfuscated and does not demonstrate malware.

Confidence: 96%Severity: 58%
AnomalyLOW
references/auto-ci-cd-preview.md

The fragment is legitimate CI/CD guidance rather than apparent malware. The main security concern is architectural: a pull-request-controlled infrastructure program is executed while cloud and Pulumi credentials are available. This can permit unauthorized cloud actions or credential exposure if an untrusted or compromised same-repository pull request is processed. Use isolated preview credentials with minimal read-only permissions, restrict secrets for untrusted contributors, pin action and dependency versions, review dependency changes, and consider approval-gated or isolated preview environments. No direct malicious behavior is shown.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:49 AM
Package URL
pkg:socket/skills-sh/pproenca%2Fdot-skills%2Fpulumi%2F@b30dfa5802448da32a91c995228c6cc1f28552d8f641fc4be7b192bc5a5aac35
Security Audit — socket — pulumi