skills/a-canary/arc-skills/docker/Gen Agent Trust Hub

docker

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill directs the agent to access ~/vault/missions.md to check mission rankings. Accessing files in directories labeled 'vault' or similar sensitive paths can result in the exposure of internal metadata or configuration to the agent's operational context.
  • [INDIRECT_PROMPT_INJECTION]: The skill uses external data from ~/vault/missions.md to guide its behavior regarding resource contention.
  • Ingestion points: ~/vault/missions.md (referenced in SKILL.md).
  • Boundary markers: Absent; there are no instructions to the agent to delimit or ignore potentially malicious instructions within the missions file.
  • Capability inventory: Docker stack management (build/run), GPU usage monitoring (nvidia-smi), and network socket inspection (ss).
  • Sanitization: Absent; the skill does not specify any validation or filtering for the ranking data retrieved from the file.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 01:03 AM
Security Audit — agent-trust-hub — docker