kargo-skill

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This SKILL.md documentation describes legitimate installation and operational steps for Kargo. It does not contain embedded malware or obfuscated code. The primary security concerns are operational: (1) the quickstart curl | sh pattern executes remote code locally and should be audited before use, and (2) examples show storing and transmitting long-lived credentials (K8s Secrets, AWS/GCP keys, PATs) which are necessary for integrations but must be secured, rotated, and scoped appropriately. No direct evidence of malicious behavior was found in the provided file itself.

Confidence: 80%Severity: 25%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:08 PM
Package URL
pkg:socket/skills-sh/julianobarbosa%2Fclaude-code-skills%2Fkargo-skill%2F@745cb200e2f52276671e9e14c7f3a6eb50cfeea9