docker-impl-compose-workflows
Warn
Audited by Snyk on Jun 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly shows runtime commands that fetch and run remote Compose files (e.g., docker compose -f https://github.com/myorg/infra.git up -d and oci://registry.example.com/project:latest), so those URLs are retrieved at runtime and their content directly controls execution of services.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata