k8s

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is largely coherent for a real Kubernetes operations skill and mostly uses official tools/endpoints, so it does not look malicious. However, it grants very broad operational power, handles live credentials, and includes an agent-runner that can fetch repos and execute commands in k8s jobs, making it high-impact and medium/high risk even without clear exfiltration or deception.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Apr 20, 2026, 10:40 PM
Package URL
pkg:socket/skills-sh/joelhooks%2Fjoelclaw%2Fk8s%2F@bd1fa0f230316807d38587699741cae2781b8036