setup-project
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is broadly aligned with Kubernetes deployment, but it grants an AI agent high-impact autonomous infrastructure powers, processes untrusted GitHub content before writing/executing changes, and handles secrets unsafely by placing them in terraform.tfvars and even committing that file. No clear malware or credential-harvesting endpoint is present, but the operational and prompt-injection risk is high.
Confidence: 88%Severity: 82%
Audit Metadata