devcontainer-setup

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Benign overall intent with coherent alignment to generating devcontainer configurations for multi-language projects. Notable risk factors are: (1) NET_ADMIN capabilities used for network isolation in the devcontainer, (2) reliance on remote/devcontainer features and GitHub Container Registry resources which introduces supply-chain risk, and (3) execution of a post_install.py script inside the container during postCreateCommand which could execute arbitrary code if not properly controlled. These risks are typical for development environments but require controls (version pinning, trusted sources, script validation) to maintain a safe supply chain.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:37 PM
Package URL
pkg:socket/skills-sh/lv416e%2Fdotfiles%2Fdevcontainer-setup%2F@15cc49136ea3ff8c769c7a21461e3d6d31dcb65c