az-aks-agent
Fail
Audited by Socket on Feb 15, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
No signs of explicit malicious behavior are present in this skill document. The declared capabilities, required credentials, install sources, and data flows are coherent with an AKS troubleshooting LLM assistant. Principal risks are data exposure to LLM providers, user misconfiguration of azure_api_base to non-official endpoints, and potential insecure handling of API keys (CLI argument, shell history). Recommend verifying the actual implementation code for: (1) that it only sends necessary diagnostic data, (2) that it uses official API endpoints by default, (3) that it documents telemetry and provides opt-out, and (4) that it avoids logging API keys or sensitive tokens.
Confidence: 80%Severity: 20%
Audit Metadata