Scaleway Deployment

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill’s broad automation fits a deployment helper, but its footprint is disproportionate: it centralizes cloud credentials and an SSH private key in GitHub Secrets, copies personal local config to servers, performs autonomous infrastructure actions, and hides operational details from the user. The largest risk is the unshown `.claude/skills/scaleway-dev/scripts/*.py` automation path, which is core to credential handling and provisioning but cannot be verified here.

Confidence: 90%Severity: 84%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:27 PM
Package URL
pkg:socket/skills-sh/clementwalter%2Fclaudine%2Fscaleway-deployment%2F@a75bb1e76518fbe956e32085fdf3c9c1588c6780