dockerfile-skill

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core Dockerfile-generation behavior is coherent, and there is no clear credential theft or malicious installer path. However, the skill has a large execution footprint: it can clone arbitrary GitHub repos, analyze untrusted content, write multiple files, run iterative docker builds, launch services, query databases, and auto-generate secret-bearing env files with minimal user interaction. That makes it a high-impact but purpose-aligned automation skill with notable indirect prompt-injection and autonomous execution risk rather than confirmed malware.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Mar 31, 2026, 10:15 AM
Package URL
pkg:socket/skills-sh/labring%2Fseakills%2Fdockerfile-skill%2F@90a47772c9eacec234dd0f12800e00cb87d386f8