docker-sandbox

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent and it relies on official Docker/OpenAI/Anthropic tooling, so this is not a malware-like mismatch. However, it instructs the agent to copy raw host auth material, store long-lived tokens, inject them into sandboxed CLIs, and run with default network access; those choices are higher-risk than necessary and only partly supported by official auth docs.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
Mar 18, 2026, 01:41 AM
Package URL
pkg:socket/skills-sh/joelhooks%2Fjoelclaw%2Fdocker-sandbox%2F@6d7e2a66ad67c061b62a1c3e05662ef8e9084166