dev-loop-dev-container

Warn

Audited by Socket on Jul 8, 2026

1 alert found:

Anomaly
AnomalyLOW
references/devcontainer-setup.md

No clear evidence of intentional malware in the shown configuration. However, the setup includes notable supply-chain and impact-amplification risks: it executes an unpinned remote script during Docker build, runs automated npm install/ci lifecycle hooks and a migration script, and bind-mounts the host’s SSH keys into the container. These factors would significantly increase harm if dependencies or upstream scripts were tampered with. Hardcoded Postgres credentials further weaken security hygiene for non-local use.

Confidence: 70%Severity: 66%
Audit Metadata
Analyzed At
Jul 8, 2026, 12:20 PM
Package URL
pkg:socket/skills-sh/j4flmao%2Fagent-skills%2Fdev-loop-dev-container%2F@587c5cc67b3258a7184d74d2d960cea2843f0e8b7d021263388ab220976e297d
Security Audit — socket — dev-loop-dev-container