devcontainer-setup
Fail
Audited by Socket on Feb 28, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
Benign overall intent with coherent alignment to generating devcontainer configurations for multi-language projects. Notable risk factors are: (1) NET_ADMIN capabilities used for network isolation in the devcontainer, (2) reliance on remote/devcontainer features and GitHub Container Registry resources which introduces supply-chain risk, and (3) execution of a post_install.py script inside the container during postCreateCommand which could execute arbitrary code if not properly controlled. These risks are typical for development environments but require controls (version pinning, trusted sources, script validation) to maintain a safe supply chain.
Confidence: 95%Severity: 90%
Audit Metadata