devops

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core repo audit and infra remediation behavior mostly fits a DevOps skill, and there is no clear remote exfiltration or malicious payload. However, the combination of autonomous no-confirmation operation, transitive sub-skill chaining, write access to infrastructure files, broad ingestion of repo content, and telemetry writes outside the repo makes the skill higher risk than a typical audit tool.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:03 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fdevops%2F@177f27bb70f901bc4f46511819b2181b5ffacf9b
Security Audit — socket — devops