bazel-build-optimization

Warn

Audited by Socket on Mar 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is largely aligned with its stated purpose of advising on Bazel setup, remote caching/execution, and performance optimization for large monorepos. Security concerns primarily arise from unverifiable external downloads (http_archive with placeholder sha256) used to acquire official Bazel rule sets. While these patterns are common in legitimate Bazel configurations, the lack of verifiable checksums and reliance on external tarballs introduces supply-chain risk. There is no evidence of credential access, unintended data exfiltration, or autonomous real-world actions. Overall, the footprint is moderately risky due to unverifiable dependencies but remains conceptually appropriate for its purpose if proper checksums are supplied and official, pinned versions are used. Recommend ensuring all external archives are from trusted sources with pinned, verifiable checksums and that no unnecessary secrets/endpoints are embedded in configuration files.

Confidence: 60%Severity: 75%
Audit Metadata
Analyzed At
Mar 8, 2026, 07:41 AM
Package URL
pkg:socket/skills-sh/EricGrill%2Fagents-skills-plugins%2Fbazel-build-optimization%2F@64c900d312eb7bfc8afb66b108af93c8256f2803