graviton-migration

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the setup of the 'armlimited/arm-mcp' Docker image. This is a third-party tool from Arm Ltd (a well-known service) used for architectural readiness scanning. The documentation provides clear instructions on pinning image tags/digests for supply chain security.
  • [COMMAND_EXECUTION]: The skill guides the user to run Docker commands (docker run --rm -i -v "$(pwd)":/workspace:ro armlimited/arm-mcp:latest) to launch the MCP server. It also references host-level tools like apx_recipe_run and sysreport_instructions. The skill includes a specific security rule (Rule 8) requiring explicit user confirmation before executing host-level commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and scan untrusted data (source code, dependency manifests, and container images) which could theoretically contain malicious instructions. The skill mitigates this by using the 'arm-mcp' tool within a Docker container mounted as read-only (:ro) and provides clear instructions on preventing secret exposure during this process.
  • [DYNAMIC_EXECUTION]: The skill describes the use of standard CI/CD patterns (GitHub Actions, AWS CodeBuild, GitLab CI) that involve executing build scripts and potentially using QEMU emulation via binfmt. These are standard development practices for multi-arch container image creation and are documented with security best practices, such as pinning action versions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 09:56 AM
Security Audit — agent-trust-hub — graviton-migration