devcontainer-setup

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/templates.md

No direct malware is evident in the supplied templates. The primary risks are intentional exposure of the host ~/.claude directory and broad workspace mounts, root-level symlink manipulation, and unvalidated command/image placeholders that could become arbitrary code execution if attacker-controlled. Review generated values and avoid mounting sensitive host configuration into untrusted containers.

Confidence: 95%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 05:10 AM
Package URL
pkg:socket/skills-sh/shipshitdev%2Fskills%2Fdevcontainer-setup%2F@3e5ae522896e7fbec1686c522e96b90e3cca5f9cb58bcec36d0d816e0e086fbf
Security Audit — socket — devcontainer-setup