deployment

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent for deployment work, and most examples align with official platform tooling. Risk comes from enabling proactive production actions, using an official-but-unsafe Fly curl|sh installer, and forwarding deployment secrets to third-party GitHub Actions (especially a Railway action pinned to @main). No strong signs of credential theft or hidden exfiltration, but the execution and trust footprint is broader than a low-risk documentation skill.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
Mar 18, 2026, 02:40 AM
Package URL
pkg:socket/skills-sh/mgd34msu%2Fgoodvibes-plugin%2Fdeployment%2F@2f78c3b10596e3525a07146effc47293c7c80626