docker

Warn

Audited by Socket on Sep 6, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/install.sh

This module is primarily a legitimate Docker installation helper, with one prominent supply-chain risk: it downloads and executes a remote shell script as root from `https://get.docker.com` without performing integrity verification (no hash/signature pinning). No clear malicious payload behavior is visible in the snippet itself (no exfiltration/persistence/credential theft), but the high-privilege remote-code-execution pattern warrants careful review and controlled execution environment.

Confidence: 66%Severity: 60%
Audit Metadata
Analyzed At
Sep 6, 2026, 10:42 AM
Package URL
pkg:socket/skills-sh/klh%2Fspeedy-claude%2Fdocker%2F@ab07cfb93f8fcb98941ded864cc709ffcc0dfab50522cccbc1454c79cab57301
Security Audit — socket — docker