kubernetes-deployment

Warn

Audited by Socket on Feb 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] [Documentation context] Credential file access detected The report is broadly benign and aligned with a local development Kubernetes scaffold. Improvements focus on securing image provenance (pin/digest instead of latest), ensuring secret management practices (avoid placeholder secrets in shared repos), and clarifying installation integrity checks for the dev tooling. No evidence of malicious behavior was found; the main concerns are operational security and reproducibility for development workflows. LLM verification: [LLM Escalated] No explicit malicious code was found in the manifests or documentation. The skill is coherent: manifests and env injection match the stated purpose. Primary security issues are supply-chain/install patterns (curl install of minikube binary, unpinned 'go install ...@latest' for kubectl-ai) and the normal sensitivity of kubeconfig and Kubernetes Secrets. Recommend: pin tool versions or provide checksums, warn users to review downloaded binaries, and avoid placing production secrets in unencrypted

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 21, 2026, 12:27 PM
Package URL
pkg:socket/skills-sh/maneeshanif%2Ftodo-spec-driven%2Fkubernetes-deployment%2F@150b53aeec9976ed86f1e86b37b9047730045929