check-production

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The health-check fragment appears aligned with its stated purpose: gather production telemetry from Sentry, Vercel, health endpoints, and CI, then produce a prioritized report for triage. However, there are notable operational risks due to error-suppression patterns and dependency on externally sourced scripts/CLI tools. To improve safety and reliability, implement script integrity checks (hash verification, signing), avoid blanket 2>/dev/null in production, and centralize secrets management for CLIs. Overall assessment: moderate risk from environment/toolchain dependencies; no concrete malicious activity detected in the fragment itself.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 07:20 AM
Package URL
pkg:socket/skills-sh/phrazzld%2Fclaude-config%2Fcheck-production%2F@39100a95f3e4bfd47b20624f86166bbbf3c2d332