eks

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is coherently aligned with its stated purpose of automating Phase Console deployment on AWS EKS via Helm, including lifecycle steps from prerequisites to deployment and optional secret management flows. The footprint shows legitimate operational capabilities (eksctl, kubectl, helm, AWS CLI) and structured secret handling, but it carries notable supply-chain and privilege considerations: automated cluster provisioning and secret manipulation with high-privilege commands; reliance on external manifests and Helm repositories; and sensitive data flows into infrastructure provisioning processes. The design attempts to mitigate hard-coded secrets by using EDIT_ME placeholders and on-demand generation, but the overall workflow remains high-privilege and externally sourced, which warrants cautious usage and strict access control. Overall security risk is moderate to high due to privilege and data-flow exposure, with no explicit malware indicators observed in the fragment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 12:31 PM
Package URL
pkg:socket/skills-sh/phasehq%2Fai%2Feks%2F@8c0819f592b2b5542535f4aad274459d3f5ce139