skaffold-standards

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is primarily documentation and configuration guidance for Skaffold with dotenvx and OrbStack. Functionality and examples align with the stated purpose (using dotenvx to decrypt env values and generate Kubernetes Secret manifests for local development). The main security concerns are operational/supply-chain rather than immediate malicious code: the installer recommendation (curl | sh) is a high-risk download-and-execute pattern; writing plaintext secrets to k8s/app-secrets.yaml and advising storing DOTENV_PRIVATE_KEY in ~/.zshrc are insecure practices that increase secret exposure risk. Skaffold hooks executing shell commands is expected for this use case but means repository-provided configs can execute arbitrary host commands, which is a general risk when running untrusted repos. Overall I classify this as suspicious/vulnerable due to supply-chain and secret-handling practices, not confirmed malware.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 07:09 PM
Package URL
pkg:socket/skills-sh/laurigates%2Fclaude-plugins%2Fskaffold-standards%2F@3dd3b94e363c29222bcb2364d9894a8d50103d9e