rke2-operations

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment describes legitimate RKE2 maintenance activities (certificate rotation, version upgrades, System Upgrade Controller usage). However, the inclusion of remote installer execution via curl | sh and deployment of privileged upgrade pods that mount host filesystems and have elevated capabilities constitutes a significant risk vector for supply-chain compromise or post-compromise action if not tightly controlled, signed, and verified. The presence of remote upgrade tooling (GitHub releases, update channels) without explicit cryptographic verification or signed attestation increases risk. Overall, the content is aligned with its stated purpose but exhibits dangerous patterns (remote executable installation, privileged host access) that justify labeling as SUSPICIOUS with high caution and require strict safeguards (signature verification, pinned versions, audit logs, and restricted networking).

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 04:46 AM
Package URL
pkg:socket/skills-sh/sigridjineth%2Fkubespray-skills%2Frke2-operations%2F@09a3f1b2bd404db86fca27f5918cf8b035522345