docker-local

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] [Documentation context] Installation of third-party script detected Benign. The code is a development guidance/documentation for Docker-based Drupal local setups. The only caveat is the presence of hardcoded default credentials in the documentation (e.g., MYSQL_ROOT_PASSWORD: root). If this content is intended for public distribution, consider removing or parameterizing such defaults and encouraging the use of .env or secret management to avoid leaking credentials in public repos. LLM verification: [LLM Escalated] This skill/documentation is benign in intent and appropriate for Docker-based local development, but it contains moderate security issues: example hardcoded credentials, credential exposure in Makefile commands, and unpinned external images/artifacts (COPY from composer:latest, alpine variants). Recommend: remove hardcoded passwords from examples, show safe ways to pass secrets (use .env and docker secrets), avoid embedding passwords on command lines, and pin image tags or add guidance to pin ve

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 11:28 PM
Package URL
pkg:socket/skills-sh/madsnorgaard%2Fdrupal-agent-resources%2Fdocker-local%2F@38bb50c8687dbbca437e6cbb1b261ca239cb6723