k8s-cluster-api

Warn

Audited by Socket on Mar 9, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/etcd-backup.yaml

The YAML is a legitimate backup setup that intentionally reads highly sensitive cluster data (etcd, cluster secrets) and uploads it to external cloud storage. I found no signs of obfuscated malicious code or hidden backdoors in the manifests themselves. However, the configuration inherently poses a significant data-exfiltration risk if cloud credentials or bucket permissions are misconfigured or if a backup container image is compromised. The broad RBAC and hostPath access increase the blast radius — treat this as a moderate-to-high operational security risk unless strict controls (least privilege, secure buckets, image provenance) are applied.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 9, 2026, 01:29 PM
Package URL
pkg:socket/skills-sh/itechmeat%2Fllm-code%2Fk8s-cluster-api%2F@f6584d6bc2322f45768889f0e1ce8076be9339fd