moai-cc-configuration

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The moai-cc-configuration fragment demonstrates a solid enterprise-oriented approach to AI-driven config design, secret management, and Context7 guidance. However, it introduces non-trivial security and supply-chain risks due to secret handling via environment variables, extensive network calls to Vault/Kubernetes, and Kubernetes API interactions without explicit authentication context in the snippet. The combination of multi-language components, explicit secret fields in schemas, and potential logging of sensitive data elevates risk to MEDIUM-HIGH if deployed without strict access controls, proper secret stores, and hardened API communications. Recommendations include strictly scoping Kubernetes namespaces, enforcing least-privilege service accounts, pinning and validating external endpoints, masking secrets in logs, and migrating decryptSecret to a dedicated, auditable secret store with rotation and MFA where feasible.

Confidence: 92%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:08 AM
Package URL
pkg:socket/skills-sh/ajbcoding%2Fclaude-skill-eval%2Fmoai-cc-configuration%2F@8395b4f1cb29e6f9d66fbe02b39042f1de7b6b47