promotion-pipeline

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is a documentation/operational guide for an OCI artifact promotion pipeline. There is no embedded malicious code or supply-chain download-and-execute pattern. The main security concerns are operational: it requires high-privilege GitHub tokens (repo and packages scopes) and access to kubeconfig files; improper handling of those credentials (leakage, overly-broad scopes, or exposing them to an automated agent) would enable repository manipulation and cluster control. Follow best practices: minimize token scopes, store secrets in secure vaults, avoid echoing tokens in shell history, and limit automated access to kubeconfigs.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 03:05 PM
Package URL
pkg:socket/skills-sh/ionfury%2Fhomelab%2Fpromotion-pipeline%2F@8c9f831c7350856315f9e95eeb2b67d50552bd2b