docker-to-sealos

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
references/example-guide.md

No direct evidence of overt malware (e.g., backdoor code or exfiltration behavior) is present in the provided YAML; the primary security issue is sensitive credential handling. The deployment hardcodes multiple credential-like values into container environment variables (`ONEAPI_KEY` with an `sk-...` format, plus static `TOKEN_KEY`/`ROOT_KEY`) instead of sourcing them from declared template inputs or Kubernetes Secrets, and it appears to mismatch the declared `openai_key` input wiring. This creates a significant risk of default/constant credentials and weak authentication across deployments. Treat the template as high risk and require removal/replacement of hardcoded secrets before use.

Confidence: 66%Severity: 72%
Audit Metadata
Analyzed At
Apr 13, 2026, 06:14 AM
Package URL
pkg:socket/skills-sh/zjy365%2Fseakills%2Fdocker-to-sealos%2F@a119d85d0934bf538181250fd3af554641910638