cluster-ops

Warn

Audited by Socket on Feb 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] [Documentation context] Credential file access detected This SKILL is an operational runbook for cluster lifecycle and maintenance. It is internally consistent: the capabilities (kubectl/oc/etcdctl/cloud CLIs) match the stated purpose. It does require high privileges and direct access to sensitive artifacts (etcd certs, snapshots, cloud credentials). No explicit malicious behavior or obfuscated code is present in the provided content, but the referenced scripts/ and backup upload/storage configuration are trust boundaries that must be audited. Treat this skill as functionally necessary for operators but high-risk from a supply-chain and credential-exposure perspective: only grant the minimum required privileges, audit the scripts referenced (scripts/*.sh), protect etcd credentials, and ensure backups are stored securely. LLM verification: [LLM Escalated] This skill is coherent and aligned with its stated purpose: cluster lifecycle and operations across several providers. It legitimately needs access to kubeconfig and cloud credentials. I found no signs of hidden exfiltration, third-party proxying, or obfuscated malicious code in the provided content. The primary risks are operational: the skill requires high-privilege credentials and invokes commands that can be destructive (etcd restores, node deletion, scaling, draining). The referenced helper

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 24, 2026, 06:59 PM
Package URL
pkg:socket/skills-sh/kcns008%2Fcluster-agent-swarm-skills%2Fcluster-ops%2F@80bf34105cc77b9f0d1fa7883223a13aba6d4032