create-docker-skill
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core scaffolding purpose is plausible and mostly aligned, but the skill explicitly manufactures a security override to whitelist subprocess and network behavior, which is broader and less trustworthy than a normal template generator. Immediate data exfiltration is not evident, yet the skill is designed to reduce future security friction for container-executing skills and references an unclear audit-plugin.
Confidence: 83%Severity: 63%
Audit Metadata