zeabur-update-service

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill coherently implements a narrowly-scoped workflow for updating environment variables and restarting a single service without redeploy. It leverages the Zeabur CLI via npx (official registry) to perform actions that touch service configuration and state. The main security considerations are: potential exposure of env-var values via shell history/logs, reliance on an external binary fetched at runtime (npx zeabur@latest), and unclear handling of authentication/credentials within the CLI and logs. Overall, the footprint is proportionate to the stated purpose but warrants caution due to credential handling and runtime binary download patterns. Classify as SUSPICIOUS to BENIGN: leaning toward SUSPICIOUS due to credential exposure risks and external binary execution, but not clearly malicious based on the provided information.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 12:53 PM
Package URL
pkg:socket/skills-sh/zeabur%2Fzeabur-claude-plugin%2Fzeabur-update-service%2F@775a291e132144c83af64804ea8a9485973c6662