check-production
Warn
Audited by Socket on Mar 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The health-check fragment appears aligned with its stated purpose: gather production telemetry from Sentry, Vercel, health endpoints, and CI, then produce a prioritized report for triage. However, there are notable operational risks due to error-suppression patterns and dependency on externally sourced scripts/CLI tools. To improve safety and reliability, implement script integrity checks (hash verification, signing), avoid blanket 2>/dev/null in production, and centralize secrets management for CLIs. Overall assessment: moderate risk from environment/toolchain dependencies; no concrete malicious activity detected in the fragment itself.
Confidence: 75%Severity: 75%
Audit Metadata