routeros-qemu-chr

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/github-actions-ci.md

No direct malware or intentional destructive payload is evident. The material documents a legitimate RouterOS CI workflow, but it contains significant security weaknesses: unverified remote artifacts are executed, KVM permissions are broadened to world-writable, guest access uses empty credentials and disabled host-key verification, forwarded services may be exposed, and the job can push to `main`. These should be hardened with pinned versions and checksums/signatures, validated inputs, restricted KVM permissions, explicit localhost binding, non-default credentials, host-key verification, and least-privilege repository permissions.

Confidence: 96%Severity: 66%
Audit Metadata
Analyzed At
Sep 16, 2026, 01:15 PM
Package URL
pkg:socket/skills-sh/tikoci%2Frouteros-skills%2Frouteros-qemu-chr%2F@d98100f5bfd3a55cb7c7cc25e17eda29aa27c9a8c6310241137e3b387860b848
Security Audit — socket — routeros-qemu-chr