docker

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/monorepo-builds.md

No direct malicious behavior is present in the supplied documentation. The most significant issue is the claim that Docker `ARG` credentials do not persist: tokens used in `RUN` commands may be exposed through image history, build metadata, logs, or exported cache. Use BuildKit secret mounts for remote-cache credentials, pin and verify pnpm/turbo versions, and use a production-only dependency deployment for the runtime image. The fragment itself contains no obfuscated payload or evident malware.

Confidence: 97%Severity: 55%
AnomalyLOW
references/compose.md

No malware or deliberate supply-chain attack is evident. The examples contain security risks if used unchanged: plaintext and weak database credentials, publicly exposed database and Redis ports, plaintext environment-file secrets, broad development bind mounts, debug service exposure, and mutable image tags. These are configuration and operational risks rather than malicious behavior.

Confidence: 99%Severity: 68%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:51 AM
Package URL
pkg:socket/skills-sh/oakoss%2Fagent-skills%2Fdocker%2F@e93252d43f45e837b0b0d535bc7c6754ba6f98db9b5cb753cdf82a73261f8939
Security Audit — socket — docker