docker-workflow

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/docker-compose.yml

The file itself is configuration and does not contain explicit malicious code, obfuscated payloads, or direct backdoors. However it contains multiple insecure configurations (hard-coded weak credentials, exposed management ports, disabled Elasticsearch security, host volume mounts that run init scripts) that increase the risk of compromise or data exposure. Treat this as a moderate security risk that requires remediation of secrets, network exposure, image pinning and volume isolation before production use.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Feb 26, 2026, 09:30 PM
Package URL
pkg:socket/skills-sh/icartsh%2Ficartsh_plugin%2Fdocker-workflow%2F@54cf4c56a089e9b03e4fe126c1b6bbbff8c74661