Scaleway Deployment
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS. The skill’s broad automation fits a deployment helper, but its footprint is disproportionate: it centralizes cloud credentials and an SSH private key in GitHub Secrets, copies personal local config to servers, performs autonomous infrastructure actions, and hides operational details from the user. The largest risk is the unshown `.claude/skills/scaleway-dev/scripts/*.py` automation path, which is core to credential handling and provisioning but cannot be verified here.
Confidence: 90%Severity: 84%
Audit Metadata