docker

Warn

Audited by Snyk on Aug 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Exposed runtime path: scripts/verify.sh reads and grep/scans free-form text from user-supplied local files ($DIR/Dockerfile, $DIR/compose.yaml, and $DIR for trivy config .), so outsider-authored Dockerfile/Compose content is directly ingested at runtime.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The Python Dockerfile snippet copies from and installs ghcr.io/astral-sh/uv:latest and then runs its uv binary during build (COPY --from=ghcr.io/astral-sh/uv:latest ... and RUN ... uv sync), so the image at ghcr.io/astral-sh/uv:latest is fetched at build time and executes remote code.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 6, 2026, 09:37 PM
Issues
2
Security Audit — snyk — docker