deployment-rollback

Warn

Audited by Socket on Feb 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected The improved review concludes that this is a feature-rich yet risk-prone deployment rollback tool. It is not malicious by design but requires significant hardening before safe public use: secret redaction, restricted IO, auditable and scoped privileges, deterministic CLI versions, and secure checkpoint handling. Consider delivering as an internal, tightly-scoped utility with explicit provenance and robust access controls rather than a general-purpose public package. LLM verification: This skill appears functionally legitimate for its stated purpose (deployment rollback across multiple platforms). It does not contain obvious remote exfiltration, obfuscated code, or direct malicious payloads. However, it performs many high-privilege operations and writes sensitive data (environment variables, DB schema, logs, cluster configs) to local checkpoint/cache files without encryption or explicit guidance to secure or exclude them from source control. That creates a real risk of creden

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 21, 2026, 12:27 PM
Package URL
pkg:socket/skills-sh/manastalukdar%2Fclaude-devstudio%2Fdeployment-rollback%2F@ea7a47e6f04676236786375975765f9a07a43fc1