cluster-report

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's described capabilities, prerequisites, and data flows are largely coherent with its stated purpose of multi-cluster OpenShift health reporting. Data collection uses officially named MCP tools, with results written to transient files and assembled into a manifest for downstream processing. Credentials are limited to KUBECONFIG context access and are explicitly protected in documentation. Overall risk is low to moderate given the sensitive nature of cluster credentials and local data persistence, with no clear evidence of credential forwarding to untrusted binaries or exfiltration beyond internal MCP tooling. Treat as SUSPICIOUS only to the extent of ensuring disciplined handling of KUBECONFIG data and /tmp persistence; otherwise, BENIGN.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 04:05 PM
Package URL
pkg:socket/skills-sh/RHEcosystemAppEng%2Fagentic-collections%2Fcluster-report%2F@9f1ec43273d8b285cc2cc5c943363b7565a076db