docker

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the os.shell.run tool to execute docker commands. This is the primary function of the skill for managing containers, images, and volumes.
  • [COMMAND_EXECUTION]: Explicit safety rules are defined in the skill instructions. Rule 1 and Rule 2 mandate user confirmation for operations like stop, rm, rmi, prune, and compose down to prevent accidental data loss or service interruption.
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates security awareness regarding untrusted data. Rule 5 explicitly instructs the agent to treat image and container contents as untrusted and to avoid acting on embedded data without user confirmation.
  • [PRIVILEGE_ESCALATION]: The skill follows the principle of least privilege by recommending that the user manually starts the Docker daemon or installs the software if missing, rather than attempting to execute privileged installation commands automatically.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 07:29 PM
Security Audit — agent-trust-hub — docker