docker-development

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Security
SecurityMEDIUM
examples/docker-compose.sample.yml

No direct evidence of intentional malware logic is present in this Compose configuration. However, it intentionally includes multiple critical deployment anti-patterns that substantially increase security risk: Docker socket exposure, privileged container mode, hardcoded secrets, broadly exposed ports (including debug and management UI), host networking, and unpinned :latest image tags. If any referenced service/container is compromised, these settings can enable high-impact host/container control. Do not deploy as-is outside a controlled, isolated test environment.

Confidence: 74%Severity: 93%
Audit Metadata
Analyzed At
Apr 3, 2026, 11:13 AM
Package URL
pkg:socket/skills-sh/borghei%2Fclaude-skills%2Fdocker-development%2F@81b8bde0e2a3f76c1ca823f641e7b45cedc90c71