gitops-workflow

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This GitOps skill is largely documentation and examples for installing and configuring ArgoCD and Flux. However, it contains several supply-chain and privilege-escalation risks: an explicit curl|bash installer executed with sudo, direct application of remote manifests, and instructions that retrieve Kubernetes secrets and read/write local agent memory files. Those patterns are common in quickstart guides but present real supply-chain and credential-exposure risks if an agent or user executes them automatically or in CI without pinning or verification. Recommendation: avoid blindly executing curl|bash; pin remote manifests to commit SHAs; avoid printing secrets to shared logs; require explicit user confirmation before performing installs, applying manifests, or reading/writing local memory files.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 02:04 PM
Package URL
pkg:socket/skills-sh/oimiragieo%2Fagent-studio%2Fgitops-workflow%2F@6bfcfd78b69db015bfac89a8b7a2b2fef95a8a63