phase-9-deployment

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill aligns with a production deployment focus, detailing CI/CD, environment separation, and deployment targets (Vercel, Kubernetes). Its data flows and credential handling are coherent with production workflows, and the use of Vault/AWS Secrets Manager is appropriate. Some enhancements would improve safety and compliance: explicit least-privilege role definitions, secret-scoping per environment, secret masking/log redaction in logs, and a formal secret rotation strategy. Overall, the footprint is benign and proportionate to its stated purpose, with moderate security risk primarily around secret management hygiene if not correctly configured.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 04:57 PM
Package URL
pkg:socket/skills-sh/popup-studio-ai%2Fbkit-claude-code%2Fphase-9-deployment%2F@de1a011792822587ce38fbcdab046cff3a8fa74f