write-helm-chart

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This Helm chart skill is primarily instructional and the templates/values described are consistent with the stated purpose of producing production-ready Helm charts. There are no code-level obfuscation or embedded backdoors in the supplied YAML content. The main security concerns are operational/supply-chain: (1) the recommended curl|bash installer for Helm is a download-and-execute pattern that raises supply-chain risk and should be replaced with a pinned, verified installer or package-managed install in high-security environments; (2) Helm hooks run arbitrary container commands inside the cluster and can have high impact if the hook images/commands or service account permissions are malicious or overly permissive; and (3) registry login and chart publishing steps require careful secret handling and trusted repository management. Overall, the content appears benign for its purpose but contains standard operational risks that make it moderately risky from a supply-chain perspective if used without secure practices.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 10:55 PM
Package URL
pkg:socket/skills-sh/pjt222%2Fdevelopment-guides%2Fwrite-helm-chart%2F@a30e5dada76b7f11b95cf06973324b8cdd9c808e