using-devops-skills

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The file itself is not a direct exploitation payload (no clear network exfiltration, reverse shells, or hard-coded credentials). However, it represents a high-risk governance manifest: coercive mandatory invocation and an instruction to avoid inspection (Do not use Read) materially increase supply-chain and operational risk. If downstream skills are compromised, this manifest would accelerate and expand impact. Treat as SUSPICIOUS: require human-in-the-loop approval, transparency (allow Read/audit), provenance controls (signing/allowlisting), and scoped invocation rules before deploying in any production or security-sensitive runtime.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:03 PM
Package URL
pkg:socket/skills-sh/lgbarn%2Fdevops-skills%2Fusing-devops-skills%2F@68d739c59ddd7dc125b99f21491f577bfbbed621