devops-specialist

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/domains/github-platform/bootstrap/SKILL.md

该技能目的与能力基本一致,主要是在本地仓库内生成 GitHub 配置。主要风险来自运行时从未公开审查的 template-catalog.md 指定仓库执行 git clone,且未见版本固定或签名校验;这更像供应链/完整性风险,而非明确恶意或凭证窃取。综合判定为 SUSPICIOUS。

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 16, 2026, 03:10 AM
Package URL
pkg:socket/skills-sh/prorise-cool%2Fprorise-claude-skills%2Fdevops-specialist%2F@4277b023f053805af929b5034e931ef1855fc820