k8s

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The deployment fragment presents a robust, largely standard Kubernetes deployment workflow for Phase Console with reasonable security-conscious patterns (no in-chat secrets, randomized values). However, it entails notable supply-chain and operational risks due to unpinned external artifacts, autopilot execution, and reliance on user-furnished placeholders. Treat as BENIGN but with elevated risk; implement mitigations such as manifest pinning, signature verification, per-step approvals, and stricter secret handling.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 12:31 PM
Package URL
pkg:socket/skills-sh/phasehq%2Fai%2Fk8s%2F@16cca847ff278ebc0d11a522558ac7c50a6165c1