devops-infra-scaffold

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code fragment represents a comprehensive, template-driven scaffolding skill for generating devops infrastructure artifacts (CI/CD workflows, Dockerfiles, deployment configs) from a tech stack context. There is no indication of malicious behavior, credential harvesting, or insecure data flows within the fragment itself. The heavy use of interactive prompts and multi-phase generation aligns with governance and correctness requirements, though it introduces potential for misconfigurations if inputs are incomplete. Template hygiene and secure pinning of downstream tools remain critical. Overall, the footprint is benign and proportionate to its stated purpose, with moderate security risk due to template integrity and complexity of generated artifacts.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 08:26 PM
Package URL
pkg:socket/skills-sh/parhumm%2Fjaan-to%2Fdevops-infra-scaffold%2F@c6555cc15663a391787749e023b973b3e8f03156