deploy-app

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match Kubernetes deployment orchestration, but its footprint is high-impact: it can deploy arbitrary third-party charts, modify repo state, push branches, and create PRs, while also referencing other skills and processing external research. No direct credential-harvesting or hidden exfiltration is evident, so this is not confirmed malware; the main concerns are supply-chain exposure from chart sources and autonomous real-world actions.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 27, 2026, 07:16 PM
Package URL
pkg:socket/skills-sh/ionfury%2Fhomelab%2Fdeploy-app%2F@711e6d509592f5dc6713f089db6055841b41e933