ansible-validator
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
AnomalyAnomalytest/playbooks/bad-playbook.yml
LOWAnomalyLOW
test/playbooks/bad-playbook.yml
This playbook contains multiple insecure patterns and misconfigurations (hardcoded password, unquoted variable in shell leading to command injection risk, TLS validation disabled for downloads, world-writable script file, unnecessary privilege escalation, handler mismatch, OS-conditional logic missing). These are security and operational risks that should be fixed, but the fragment does not contain clear malicious logic (no obfuscated payloads, no network exfiltration or reverse shell code shown). Treat it as insecure/unsafe to use in production until remediated.
Confidence: 90%Severity: 60%
Audit Metadata