dotnet-core-expert

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the dotnet CLI for essential development tasks, including compiling source code (dotnet build), running unit and integration tests (dotnet test), and managing Entity Framework migrations (dotnet ef).
  • [EXTERNAL_DOWNLOADS]: The Dockerfile provided in references/cloud-native.md downloads official .NET 8 SDK and runtime images from the Microsoft Container Registry (mcr.microsoft.com).
  • [CREDENTIALS_UNSAFE]: A reference file for cloud-native development contains a hardcoded password (YourStrong@Passw0rd) within a sample Docker Compose file. While used as an example, this represents a practice of embedding secrets in configuration files.
  • [DATA_EXFILTRATION]: Example configurations in the cloud-native guidance include network requests to non-whitelisted domains for health monitoring (api.external-service.com) and external logging/tracing services (seq:5341, jaeger:4317).
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze user requirements and generate corresponding C# code and architecture. This creates an attack surface where malicious instructions provided in the requirements could potentially influence the generated output or the commands executed by the agent.
  • Ingestion points: Requirement analysis and design phases described in SKILL.md.
  • Boundary markers: None identified.
  • Capability inventory: Execution of shell commands via the dotnet CLI and network operations for application observability.
  • Sanitization: No input validation or sanitization logic is specified for the requirements data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — dotnet-core-expert