schema-e2e-validation

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md is documentation for a schema E2E validation workflow using Earthly, Docker/Colima, and Doppler for secret injection. The described behaviors are coherent with the stated purpose: generating types/DDL/docs locally without secrets and running full validation against ClickHouse Cloud when read-only ClickHouse credentials are provided via Doppler. No evidence of download-and-execute attacks, unknown remote exfiltration endpoints, hardcoded secrets, obfuscated payloads, or commands that would harvest arbitrary host credentials appears in the provided text. The main security considerations are operational: transient creation and forwarding of secrets via a temporary file (the wrapper script must securely handle file permissions and cleanup), and the fact that allowed-tools includes Bash which grants the ability to run arbitrary commands — appropriate caution is required when granting an automated agent shell execution plus Doppler token access. Overall this appears functionally appropriate for its purpose, with moderate warnings around secrets handling hygiene.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 03:54 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fschema-e2e-validation%2F@4e643bdf29a8026beeb3f10988b9851652994b0e