homelab-helper

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment is a legitimate, detailed homelab deployment guide outlining Docker-compose patterns, reverse-proxy setup, and HA integration. It is not malware, and there is no active data exfiltration or exploit code. However, the configuration choices (host networking and privileged container for Home Assistant, environment-based secrets, and dashboard exposure) introduce elevated security risk. The footprint is coherent with its stated purpose (self-hosted homelab guidance) but remains high risk if deployed in production or untrusted environments. Recommend adopting secrets management, minimizing privileged/host-network usage, implementing least-privilege networking, and tightening exposure where feasible.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 04:48 AM
Package URL
pkg:socket/skills-sh/arosenkranz%2Fclaude-code-config%2Fhomelab-helper%2F@06b0a3e6a288be606b8481f1fa4df5b9a7471113