dotnet-core-expert
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use the
dotnetCLI for essential development tasks, including compiling source code (dotnet build), running unit and integration tests (dotnet test), and managing Entity Framework migrations (dotnet ef). - [EXTERNAL_DOWNLOADS]: The Dockerfile provided in
references/cloud-native.mddownloads official .NET 8 SDK and runtime images from the Microsoft Container Registry (mcr.microsoft.com). - [CREDENTIALS_UNSAFE]: A reference file for cloud-native development contains a hardcoded password (
YourStrong@Passw0rd) within a sample Docker Compose file. While used as an example, this represents a practice of embedding secrets in configuration files. - [DATA_EXFILTRATION]: Example configurations in the cloud-native guidance include network requests to non-whitelisted domains for health monitoring (
api.external-service.com) and external logging/tracing services (seq:5341,jaeger:4317). - [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze user requirements and generate corresponding C# code and architecture. This creates an attack surface where malicious instructions provided in the requirements could potentially influence the generated output or the commands executed by the agent.
- Ingestion points: Requirement analysis and design phases described in
SKILL.md. - Boundary markers: None identified.
- Capability inventory: Execution of shell commands via the
dotnetCLI and network operations for application observability. - Sanitization: No input validation or sanitization logic is specified for the requirements data.
Audit Metadata