terragrunt-validator

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent for Terragrunt validation and uses largely official tooling, but its footprint is broader than its title suggests: it includes apply/destroy, arbitrary exec with auth context, and external doc retrieval combined with command execution. No clear credential theft or attacker-controlled endpoint is present, so this is not malicious, but it carries meaningful operational and supply-chain risk.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Mar 28, 2026, 06:19 PM
Package URL
pkg:socket/skills-sh/akin-ozer%2Fcc-devops-skills%2Fterragrunt-validator%2F@afacd3d29775b513488c7b4856266a25eb0d9a71