setup-container-registry

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The material is a comprehensive, well-aligned guide for configuring and securing container registries across ghcr.io, Docker Hub, and Harbor. The primary risk is exposure of credentials and secrets through example configurations and documentation. An improved version should replace hardcoded secrets with placeholders, enforce secret management best practices, pin tool versions and verify integrity, and document rotation and access controls. Overall, the plan is sound if secret handling and tool verification are addressed to reduce supply-chain and access risks.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 10:54 PM
Package URL
pkg:socket/skills-sh/pjt222%2Fdevelopment-guides%2Fsetup-container-registry%2F@72036c16416c942ce40f910df7ca6091ceffd6ef