docker-development
Warn
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The file
SKILL.mdcontains a relative path traversal sequence (../../../). This pattern is a security risk as it typically indicates an attempt to access sensitive files or internal project configurations stored outside of the restricted skill environment. - [PROMPT_INJECTION]: By providing a filesystem path as the primary content instead of valid instructions or YAML frontmatter, the skill attempts to redirect the agent's context or load instructions from an unverified location on the host system, bypassing standard constraints.
Audit Metadata