Pod CrashLoop Runbook

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated Kubernetes diagnostic purpose is coherent, but the installation model is a transitive trust chain: an unpinned external `npx skills` CLI from a different org installs skill content from another repo. I see no clear malicious data exfiltration or disproportionate permissions in the provided text, but the remote install path and publisher mismatch raise medium supply-chain risk.

Confidence: 83%Severity: 62%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:37 AM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fpod-crashloop-runbook%2F@3c8fe40022643a90f3a74c9987a7a954aed78345