vps-setup-for-vibe-coders

Warn

Audited by Socket on Sep 24, 2026

3 alerts found:

Anomalyx3
AnomalyLOW
references/compose-templates.md

The visible code does not indicate malware or intentional supply-chain sabotage. The principal security concern is deliberate exposure of root-equivalent Docker write access to Portainer, mitigated here by loopback binding and SSH access but still requiring strong authentication and host protection. Passing the database password in a process argument creates a local secret-exposure risk. The default-privilege comment may overstate coverage for tables created by other migration owners. Image tags should ideally be pinned by digest for stronger supply-chain integrity.

Confidence: 93%Severity: 57%
AnomalyLOW
scripts/healthcheck.sh

The code is an operational security regression script, not apparent malware. Its primary risks are unsafe nested shell and SQL construction in the PostgreSQL check, execution of configurable or unpinned Docker images, and use of high-privilege Docker and sudo operations. These issues should be mitigated by validating and safely quoting identifiers, using PostgreSQL parameters, pinning images by digest, and restricting configuration ownership and execution privileges.

Confidence: 97%Severity: 58%
AnomalyLOW
references/restore.md

The fragment is a legitimate disaster-recovery runbook and contains no evident malware or supply-chain backdoor. It does include high-impact destructive commands and sensitive secret restoration. Validate all placeholders, authenticate and integrity-check backup archives, inspect tar members before extraction, explicitly verify restored roles and privileges, and protect backup contents and tunnel credentials. The security concern is procedural and operational rather than malicious behavior.

Confidence: 98%Severity: 56%
Audit Metadata
Analyzed At
Sep 24, 2026, 05:58 AM
Package URL
pkg:socket/skills-sh/anant-c%2Fskills%2Fvps-setup-for-vibe-coders%2F@f5c6399cd86a27baac35bc7427cea630be178a60e3fc15e1fcbf19c97b96547a