linux-docker

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The linux-docker skill is largely coherent with its stated purpose of handling Docker and Compose operations on Linux and applying security hardening. The footprint is proportionate for a developer-focused container tooling helper. There are mild security concerns around credential handling (storing or echoing credentials in logs/history) and potential exposure of credentials via environment variables, which warrants explicit guidance on secret management and secure workflows. No evidence of malicious behavior, unverifiable binaries, or data exfiltration patterns is present. Overall risk is low-to-moderate with respect to security due to credential handling patterns that should be mitigated by best practices.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 05:46 PM
Package URL
pkg:socket/skills-sh/alphaonedev%2Fopenclaw-graph%2Flinux-docker%2F@74569335c3af880f0aa5c2b447d2c7241ff3b22d