cloud-weaver-hermes-agent
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecurityscripts/compose/compose.yaml
MEDIUMSecurityMEDIUM
scripts/compose/compose.yaml
No direct malware or explicit malicious payload is present in this Compose fragment. The configuration has a critical intentional privilege-escalation risk: the publicly exposed ttyd service is given write access to the Docker socket, enabling authenticated terminal users or a compromised terminal container to obtain host-equivalent control. Secret exposure through the terminal, mutable image tags, and unverified third-party images add supply-chain and operational risk. Review and hardening are required before deployment.
Confidence: 98%Severity: 90%
Audit Metadata