devops-expert

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Credential file access detected All findings: [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] The fragment is a coherent, non-operational skill description intended to guide a DevOps agent. There is no code or runtime logic that reads inputs, writes outputs, or exfiltrates data. As a result, there is no malicious behavior detected in the provided material. The footprint is consistent with the stated purpose of offering best-practice guidance and decision trees for deployment and operations. LLM verification: Functionally appropriate DevOps troubleshooting skill: capabilities map to stated purpose and expected diagnostic actions. No evidence of obfuscated or explicitly malicious code, no external exfiltration endpoints. Main security concern is sensitivity: the skill suggests reading environment variables and credential files (e.g., .aws, .docker) and running high-privilege CLIs which can expose secrets or perform changes if executed without user consent or proper safeguards. Treat as potentially sen

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 01:46 AM
Package URL
pkg:socket/skills-sh/cin12211%2Forca-q%2Fdevops-expert%2F@c49524dce07ab9594e7823a2838b56b0c8273c08