kubespray-airgap

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Benign with caution. The code/documentation describes a coherent offline deployment workflow for Kubespray using kubespray-offline, including generation of a self-contained outputs/ directory, private registry setup, and offline deployment steps. While the approach of using HTTP mirrors and skipping TLS verification in some mirror configurations is appropriate for air-gapped environments, it introduces potential risk if the offline infrastructure is compromised or misconfigured. No explicit credential harvesting, remote execution, or external network calls are evident in the fragment. The overall design aligns with its stated purpose, though operators should ensure integrity verification (hashes/signatures) of offline artifacts and hardened internal network security to mitigate supply-chain and runtime risks.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 04:45 AM
Package URL
pkg:socket/skills-sh/sigridjineth%2Fkubespray-skills%2Fkubespray-airgap%2F@5f3449bb75664f20f832740199ed4872ad57f574