alz-accelerator-skill

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (deploy Azure Landing Zones with ALZ Accelerator/AVM, guide Bicep vs Terraform, bootstrap CI/CD, manage platform subscriptions) is broadly coherent with its described workflow and prerequisites. The primary security considerations center on credential handling (PATs via environment variables), access to CI/CD and VCS resources, and the potential for credential leakage through shells or logs. There are no evident malicious data exfiltration patterns or unverifiable binaries in the provided material. Overall risk is moderate (suspicious-to-moderate) due to credential handling and surface-area expansion, but the footprint remains proportionate to its stated purpose when proper secret hygiene and least-privilege controls are enforced.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 06:57 AM
Package URL
pkg:socket/skills-sh/julianobarbosa%2Fclaude-code-skills%2Falz-accelerator-skill%2F@cf7419df04518195b83d60ac4f1117fcccfc3102