DORA Metrics and DevOps Performance

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The DORA Metrics and DevOps Performance skill presents a coherent and proportionate footprint for its stated purpose: it collects standard DevOps metrics from GitHub data, computes performance levels, and outputs reports/dashboards. The credential handling is limited to a normal API token without evident exfiltration or execution of untrusted code. While there are minor data-flow complexities and a reliance on a placeholder incident source, these do not undermine the core intent. Overall, the risk posture is benign to low with reasonable credential discipline; no supply-chain, autonomous action, or data exfiltration risks are evident given the provided content.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 03:06 AM
Package URL
pkg:socket/skills-sh/doanchienthangdev%2Fomgkit%2Fdora-metrics-and-devops-performance%2F@5b20b481121d0990edaffbf275c45a92c9d6180e