setting-up-astro-project

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is documentation and configuration guidance for creating and configuring Astro/Airflow projects. It does not contain code that downloads and executes remote payloads, obfuscated logic, or direct exfiltration routines. Primary risks are operational: example cleartext credentials in airflow_settings.yaml which encourage insecure secret handling, and an example Dockerfile that installs packages from a custom package index without pinning or verification (a supply-chain risk if an untrusted index is used). Recommend removing or clearly marking example credentials, advising use of secret management (Airflow connections via environment secrets or secret backends), and recommending package pinning and verified sources for Dockerfile installs.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/astronomer%2Fagents%2Fsetting-up-astro-project%2F@51dbf4bebafae94a2634f6fa90f4c1fc51c9260d