zeabur-deployment-logs

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is coherent with its stated purpose of viewing deployment logs via the Zeabur CLI. However, there are modest security concerns around the use of npx to fetch the latest CLI from npm (supply-chain risk, potential for unpinned/unverified binaries). No credentials are required by the commands themselves, and the data flow is straightforward (CLI fetches logs and prints them). Given the absence of pinned versions and the reliance on an external executable, this skill should be treated as Suspicious rather than Benign, with a recommendation to pin the CLI version, verify checksums, and document access controls for sensitive logs.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 12:48 PM
Package URL
pkg:socket/skills-sh/zeabur%2Fzeabur-claude-plugin%2Fzeabur-deployment-logs%2F@32c7d633733e87926fc8bea4226aff49c81e66b3