databricks-asset-bundles

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill appears to be a legitimate Databricks Asset Bundles deployment/configuration repository and automation examples. The capabilities match the stated purpose. No evidence of malicious code or credential-harvesting backdoors was found. Main security considerations are operational: (1) piping an install script from raw.githubusercontent.com (convenient but a supply-chain risk if that repo is compromised), and (2) ensuring GitHub Actions secrets and branch protections are correctly configured to prevent unauthorized deploys. Treat databricks tokens as high-value credentials and avoid unnecessarily broad exposure in CI; consider pinning installer commits or using packaged installers to reduce supply-chain risk.

Confidence: 80%Severity: 28%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:19 PM
Package URL
pkg:socket/skills-sh/vivekgana%2Fdatabricks-platform-marketplace%2Fdatabricks-asset-bundles%2F@6b58eaeee46d7d0959c3bbc87eb4874c9287820c