setup-devcontainer

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core repo-scanning and devcontainer generation are coherent, and network calls target official Anthropic and Gitpod/Ona services. However, the skill’s footprint is broader than its stated setup purpose: it pushes cloud project provisioning, remote SSH verification, secret injection, and persistent personal secret configuration including SSH/GPG/gitconfig/AWS-related material. The official curl|sh installer reduces malware confidence, but the overall capability and credential scope are disproportionate for a devcontainer setup skill.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Apr 22, 2026, 03:51 PM
Package URL
pkg:socket/skills-sh/fellowship-dev%2Fdogfooded-skills%2Fsetup-devcontainer%2F@13e7cfeca5e9c553f199624737445bd92f55b49e