docker-development
Warn
Audited by Socket on Aug 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s Docker-focused capabilities are coherent, but its installation trust is not: the repo owner and documented publisher path do not line up, and the install methods add transitive trust into other agent ecosystems. I see no confirmed credential theft or malicious payload behavior in the skill content itself, but the provenance mismatch is enough to treat it as a medium-high supply-chain risk.
Confidence: 87%Severity: 74%
Audit Metadata