using-devops-skills
Fail
Audited by Socket on Feb 16, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The file itself is not a direct exploitation payload (no clear network exfiltration, reverse shells, or hard-coded credentials). However, it represents a high-risk governance manifest: coercive mandatory invocation and an instruction to avoid inspection (Do not use Read) materially increase supply-chain and operational risk. If downstream skills are compromised, this manifest would accelerate and expand impact. Treat as SUSPICIOUS: require human-in-the-loop approval, transparency (allow Read/audit), provenance controls (signing/allowlisting), and scoped invocation rules before deploying in any production or security-sensitive runtime.
Confidence: 98%
Audit Metadata