docker
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill directs the agent to access
~/vault/missions.mdto check mission rankings. Accessing files in directories labeled 'vault' or similar sensitive paths can result in the exposure of internal metadata or configuration to the agent's operational context. - [INDIRECT_PROMPT_INJECTION]: The skill uses external data from
~/vault/missions.mdto guide its behavior regarding resource contention. - Ingestion points:
~/vault/missions.md(referenced in SKILL.md). - Boundary markers: Absent; there are no instructions to the agent to delimit or ignore potentially malicious instructions within the missions file.
- Capability inventory: Docker stack management (build/run), GPU usage monitoring (
nvidia-smi), and network socket inspection (ss). - Sanitization: Absent; the skill does not specify any validation or filtering for the ranking data retrieved from the file.
Audit Metadata