dockerfile-skill

Warn

Audited by Socket on Jun 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core Dockerfile-generation behavior is coherent, and there is no clear credential theft or malicious installer path. However, the skill has a large execution footprint: it can clone arbitrary GitHub repos, analyze untrusted content, write multiple files, run iterative docker builds, launch services, query databases, and auto-generate secret-bearing env files with minimal user interaction. That makes it a high-impact but purpose-aligned automation skill with notable indirect prompt-injection and autonomous execution risk rather than confirmed malware.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 15, 2026, 03:13 AM
Package URL
pkg:socket/skills-sh/zjy365%2Fsealos-skills%2Fdockerfile-skill%2F@4ba7b11480de46d4da888b79772177fd4c612c8ed1a6cd0e977b022b60a1b223
Security Audit — socket — dockerfile-skill