setup-project

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is broadly aligned with Kubernetes deployment, but it grants an AI agent high-impact autonomous infrastructure powers, processes untrusted GitHub content before writing/executing changes, and handles secrets unsafely by placing them in terraform.tfvars and even committing that file. No clear malware or credential-harvesting endpoint is present, but the operational and prompt-injection risk is high.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Apr 10, 2026, 12:23 AM
Package URL
pkg:socket/skills-sh/ViktorBarzin%2Finfra%2Fsetup-project%2F@b9c8dec176cd7cbfd2fa127c2b6bc14f883b055a
Security Audit — socket — setup-project