vm-lifecycle-manager

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The vm-lifecycle-manager skill presents a coherent and proportionate footprint for its stated purpose: controlling VM power state within an OpenShift/KubeVirt environment with explicit user confirmation and safe restart sequencing. It relies on established tooling and cluster credentials, avoids autonomous destructive actions through confirmation, and includes state verification steps. Potential risks are moderate and primarily revolve around correct RBAC configuration, ensuring trusted source tooling, and maintaining strict handling of KUBECONFIG credentials. Overall, the design is benign with respect to security risk, though attention to supply-chain provenance of the vm_lifecycle tool and explicit network exposure details would improve assurance.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 04:05 PM
Package URL
pkg:socket/skills-sh/RHEcosystemAppEng%2Fagentic-collections%2Fvm-lifecycle-manager%2F@e655319a40784e8f5bb019f4aa47e1bea779e5f2