coolify-orchestrator

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly align with Coolify orchestration, but it enables high-impact infrastructure actions and forwards a sensitive API token to a user-specified base URL without host verification. No malware or deceptive exfiltration is evident, yet the combination of deploy/provision/restart automation plus SSH/docker exec makes it medium-risk and more than minimally scoped.

Confidence: 90%Severity: 56%
Audit Metadata
Analyzed At
Apr 18, 2026, 01:40 PM
Package URL
pkg:socket/skills-sh/fatih-developer%2Ffth-skills%2Fcoolify-orchestrator%2F@429a54521af626538be850143dd0a5d8d958475b