create-docker-skill

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core scaffolding purpose is plausible and mostly aligned, but the skill explicitly manufactures a security override to whitelist subprocess and network behavior, which is broader and less trustworthy than a normal template generator. Immediate data exfiltration is not evident, yet the skill is designed to reduce future security friction for container-executing skills and references an unclear audit-plugin.

Confidence: 83%Severity: 63%
Audit Metadata
Analyzed At
Mar 14, 2026, 09:00 AM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fcreate-docker-skill%2F@71bb686f4c99a0bd29d60f6ca25203da9a50d4be