docker-compose

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment outlines a coherent and feature-complete deployment workflow for Phase Console with automated TLS provisioning. It is technically plausible for production use but carries notable security concerns: autopilot-like execution without stepwise human verification, remote template integrity risks, and sensitive TLS material handling within containers. To reduce risk, introduce content verification (signatures/checksums), restrict and audit automated secret generation flows, namespace isolation for Docker, and explicit prompts or approvals for non-idempotent steps. Treat as Moderate-High risk until integrity controls are in place.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 12:32 PM
Package URL
pkg:socket/skills-sh/phasehq%2Fai%2Fdocker-compose%2F@43859017db2542ce07d9f5437aa9d66f5e5e1d4b