frontend-deploy-standard

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is coherent with its stated purpose and contains typical DevOps templates for building and deploying Vite frontends. It does not contain intentional malware or obvious data-exfiltration code. The main security risk is operational: the documentation's recommendation to keep .git in the Docker build context and the use of COPY . . raise the chance of accidentally including sensitive files (repository history, .env, keys) in build contexts or images that are pushed to registries. Users should prefer passing commit metadata from CI (build-args) or explicitly exclude sensitive files from the build context and carefully manage CI/deployment secrets.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 09:32 PM
Package URL
pkg:socket/skills-sh/ducter-dev%2Fmis-skills-ai%2Ffrontend-deploy-standard%2F@a333fe381c115a904182555fd3b259fe62cc662e