infra-deploy

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code fragment represents a legitimate, multi-target deployment workflow for Cal.com on GCP Cloud Run with a local Docker Compose dev path and a webhook relay integration. It relies on vault-based secret management and environment-variable deployment, which is common but introduces notable risk around public exposure via unauthenticated Cloud Run access and potential logging of sensitive values. No explicit malware indicators are present; the pattern is deployment orchestration with moderate-to-high secret-handling risk. Recommend tightening access controls (avoid --allow-unauthenticated where not needed), enabling secret redaction in logs, and enforcing least-privilege for vault access and service permissions; add secret rotation and audit trails to improve resilience.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 02:20 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Finfra-deploy%2F@5f8c6d60767d3352d75822b4893f4f758ebe09b9