kamal-deployment

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
logging.md

The provided configuration is a standard centralized logging setup that achieves structured log collection and external forwarding. It does not contain obviously malicious code, but it contains high-risk operational choices: mounting /var/run/docker.sock into the Vector container and forwarding raw container logs to external HTTP sinks without visible redaction. These choices materially increase the risk of sensitive-data exfiltration and provide a powerful privilege escalation/host-control vector. Recommend removing or tightly constraining docker.sock access, adding explicit redaction/allowlist transforms, pinning images, and implementing network and secrets controls before deploying to production.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:45 PM
Package URL
pkg:socket/skills-sh/faqndo97%2Fai-skills%2Fkamal-deployment%2F@38a1670843b7de29e38dd6a67d41dc2cf088b1fd