docker-compose

Warn

Audited by Snyk on Feb 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). This skill explicitly downloads and applies configuration files from public URLs on raw.githubusercontent.com (see Phase 4a curl commands and refs/docker-compose-deployment.md), so the agent fetches and acts on untrusted third-party content that can change runtime behavior.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).


MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). This skill instructs the agent to write and modify service/config files (nginx, docker-compose), run Docker/certbot commands, and install a cron job — autonomously changing the host's state and potentially affecting security and availability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 28, 2026, 12:30 PM