RobustaDev

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This Skill/README fragment appears to be legitimate documentation for Robusta (Kubernetes alert automation). I found no signs of code obfuscation, embedded payloads, or explicit malicious behavior. The primary security concerns are operational: destructive actions (delete_pod, node_bash_enricher) require strong RBAC controls and careful configuration; plaintext storage of sink credentials in generated_values.yaml increases risk of credential leakage if files are checked into repos; and optional SaaS/AI features (platform.robusta.dev, HolmesGPT) could exfiltrate alert/context data if a user selects hosted services rather than self-hosting. Recommend enforcing least-privilege RBAC for Robusta components, keeping generated_values.yaml out of source control or using sealed/secret management, and documenting explicit safe defaults and approvals for destructive actions.

Confidence: 80%Severity: 45%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:11 PM
Package URL
pkg:socket/skills-sh/julianobarbosa%2Fclaude-code-skills%2Frobustadev%2F@6992f2371f7e299c5f8e7605a2190784224f07ea