codebuddy-deploy
Warn
Audited by Socket on Mar 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Overall, the skill fragment is coherent with its stated purpose of guiding zero-downtime deployment, rollback, health checks, and observability for a Node/PM2/Nginx deployment. It does not contain executable malware or covert data exfiltration patterns. The primary security concerns relate to securely managing credentials (not embedding secrets in releases, restricting SSH keys, and ensuring proper access controls). Given its descriptive nature, the footprint is appropriate for a deployment skill, with moderate security risk due to potential misconfigurations in real deployments (remote access, secret handling, and rollback/reactive actions).
Confidence: 75%Severity: 75%
Audit Metadata