devops-infra-scaffold
Audited by Socket on Feb 26, 2026
1 alert found:
SecurityThe code fragment represents a comprehensive, template-driven scaffolding skill for generating devops infrastructure artifacts (CI/CD workflows, Dockerfiles, deployment configs) from a tech stack context. There is no indication of malicious behavior, credential harvesting, or insecure data flows within the fragment itself. The heavy use of interactive prompts and multi-phase generation aligns with governance and correctness requirements, though it introduces potential for misconfigurations if inputs are incomplete. Template hygiene and secure pinning of downstream tools remain critical. Overall, the footprint is benign and proportionate to its stated purpose, with moderate security risk due to template integrity and complexity of generated artifacts.