docker-expert

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard shell commands (docker version, docker info, docker ps) to perform environment detection and container status analysis.
  • [COMMAND_EXECUTION]: Includes validation routines using docker build and docker run to verify that proposed Dockerfile changes or Compose configurations are valid and functional.
  • [SAFE]: All external references are to official or well-known images from trusted registries, including Docker Hub official images (node:18-alpine, postgres:15-alpine) and Google Container Registry (gcr.io/distroless).
  • [SAFE]: The skill explicitly promotes security best practices, such as configuring non-root users, utilizing BuildKit secrets to avoid sensitive environment variables, and using Docker Scout for vulnerability scanning.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:18 PM
Security Audit — agent-trust-hub — docker-expert