cicd-deploy-pro

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill appears to be a framework-guide style tooling description for CI/CD deployment of a Next.js/Prisma/Neon project with multiple deployment targets. Its footprint is coherent with its stated purpose and uses conventional, reputable tools (pnpm, GitHub Actions, Vercel, Docker). While there are some risky patterns in examples (use of fake credentials, patches via postinstall.js, and potential log exposure), these are confined to illustrative content and do not indicate active credential harvesting or malicious data flows. Overall, the risk is low-to-moderate (benign with caveats) given the absence of unverifiable binaries, external data sinks, or credential-forwarding flows in the described material.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 01:22 AM
Package URL
pkg:socket/skills-sh/clownnvd%2Fclaude-code-skills%2Fcicd-deploy-pro%2F@65bb1e8c3297e72f59c7bd11496f6af4bd21d3e8