ci-cd-specialist

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill fragment presents a cohesive and coherent depiction of CI/CD capabilities, release automation, and deployment strategies. The code-like content consists of YAML workflows, Dockerfiles, Kubernetes manifests, and shell scripts that align with the stated purpose of a CI/CD specialist. There are no evident hardcoded secrets, and credential usage follows common patterns (GitHub Actions secrets, environment variables). The data flows from CI to registries and production endpoints appear typical for this domain, though the use of placeholder endpoints and multi-provider deployment references should be adjusted to real environments with proper access controls. The main risks are interactive hotfix/rollback prompts and potential exposure surfaces in deployment/testing flows. Recommend tightening automation to minimize manual prompts in non-interactive contexts, auditing GitHub Actions permissions, and ensuring endpoints are secured and properly restricted to intended environments.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:34 PM
Package URL
pkg:socket/skills-sh/jgarrison929%2Fopenclaw-skills%2Fci-cd-specialist%2F@e8db4f80c46eb4c768fd61bae71d53ed034e0c88