devcontainer-setup

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
resources/devcontainer.json

No explicit malicious payload is visible in this configuration fragment (no hardcoded secrets, suspicious domains, or overt exfiltration logic). However, the configuration executes an uninspected post-create script (/opt/post_install.py) and installs external components (a devcontainer feature and a VS Code extension). Combined with elevated container network capabilities (NET_ADMIN/NET_RAW) and mounting of user/agent configuration, this creates a meaningful supply-chain/setup risk that warrants review of the Dockerfile, the post_install.py script, and the referenced feature/extension source integrity and behavior.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 11, 2026, 10:21 PM
Package URL
pkg:socket/skills-sh/mwathiben%2Fhush-private-bookmarks%2Fdevcontainer-setup%2F@4ba42bce4e43e9803e79a0747c710d6fdef57bbe
Security Audit — socket — devcontainer-setup