coolify

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Benign overall with moderate security caution. The skill is coherent with its described purpose and uses standard authentication and REST API patterns. Primary concerns: default HTTP endpoint (no TLS in default URL) may expose tokens if used in insecure environments; token retrieval from local files could leak if access controls are lax or shell history is preserved. Recommend enforcing HTTPS in production, pinning/short-lived tokens, and ensuring token files are secured (restrict permissions, avoid logging commands that reveal tokens).

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:26 AM
Package URL
pkg:socket/skills-sh/spqw%2Fskill-coolify%2Fcoolify%2F@e6c7194572dfefa75497a3a45964a92df2875335