terraform-ansible

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core Terraform/Ansible capabilities match the stated IaC purpose, and most commands are normal documentation examples. Risk comes from the optional MCP integration using an unverified npx package with unclear publisher linkage, disabled SSH host key checking, and broad real-world infrastructure control. This looks like a legitimate but high-impact automation skill with meaningful supply-chain and execution-trust concerns rather than confirmed malware.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 07:16 AM
Package URL
pkg:socket/skills-sh/phuetz%2Fcode-buddy%2Fterraform-ansible%2F@35f9c17778b2cdd935f4a784ff6be96041b687b4