cloud-weaver-hermes-agent

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/compose/compose.yaml

No direct malware or explicit malicious payload is present in this Compose fragment. The configuration has a critical intentional privilege-escalation risk: the publicly exposed ttyd service is given write access to the Docker socket, enabling authenticated terminal users or a compromised terminal container to obtain host-equivalent control. Secret exposure through the terminal, mutable image tags, and unverified third-party images add supply-chain and operational risk. Review and hardening are required before deployment.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Sep 12, 2026, 03:13 AM
Package URL
pkg:socket/skills-sh/fagnerlopes%2Fcloud-weaver%2Fcloud-weaver-hermes-agent%2F@5d283def76c11c9cd204fcc032bd1d9084c4f2fde20ca8343ab923618d9a2e31
Security Audit — socket — cloud-weaver-hermes-agent