tzurot-deployment

Warn

Audited by Socket on Feb 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Download or install from free hosting/deployment platform detected All findings: [HIGH] supply_chain: Download or install from free hosting/deployment platform detected (SC007) [AITech 9.1.4] [HIGH] supply_chain: Download or install from free hosting/deployment platform detected (SC007) [AITech 9.1.4] [HIGH] supply_chain: Download or install from free hosting/deployment platform detected (SC007) [AITech 9.1.4] The guidance is appropriate for production-like deployment operations, with strong emphasis on secret management and avoidance of internal data exposure. While no malware or suspicious activity is evident, the document’s handling of secrets and the LOCAL migrations warning should be clearly followed to prevent misconfigurations or accidental exposure in real deployments. LLM verification: This SKILL.md is an operational deployment/runbook for Railway with instructions that match its stated purpose. I found no evidence of intentional malware, obfuscation, or third-party credential-harvesting proxies. The primary risk is operational: the documented convenience of injecting production DB credentials into arbitrary local scripts (pnpm ops run / pnpm with-env) can lead to data exposure or exfiltration if scripts are untrusted. Treat the ability to execute one-off scripts with producti

Confidence: 78%Severity: 75%
Audit Metadata
Analyzed At
Feb 18, 2026, 01:45 PM
Package URL
pkg:socket/skills-sh/lbds137%2Ftzurot%2Ftzurot-deployment%2F@8f1f2ee575539206da2a48df80108242eddb9eb1