docker-privesc

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is internally coherent but highly dangerous: it is an offensive privilege-escalation playbook that enables an AI agent or operator to escape Docker containers and obtain host root. Install provenance is mostly official and there is no third-party credential forwarding, so this is not confirmed malware; however, the capability itself is an AI-agent exploit skill with destructive, persistence-enabling host actions, making overall security risk high.

Confidence: 95%Severity: 93%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fdocker-privesc%2F@2f33d0c2da283db297482fde976a0f7f8c01878c498c42b68478d4f14afc203d
Security Audit — socket — docker-privesc