docker-development

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The example files examples/Dockerfile.sample and examples/docker-compose.sample.yml contain hardcoded dummy credentials (e.g., DATABASE_URL=postgres://admin:s3cretPass@db.internal:5432/appdb, API_KEY=sk-prod-a8f3b2c1d4e5f6a7b8c9d0e1f2a3b4c5, and DB_PASSWORD=supersecret123). These are clearly labeled as 'ANTI-PATTERN' and 'deliberate bad practices' for demonstration and testing purposes, rather than functioning credentials for the skill's operation.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted content from user-provided Dockerfiles and Compose files which could contain embedded instructions intended to influence the agent.\n
  • Ingestion points: The scripts scripts/dockerfile_analyzer.py (line 330) and scripts/compose_validator.py (line 309) ingest raw file content through Path.read_text().\n
  • Boundary markers: There are no explicit markers or prompt engineering instructions used to delimit the external content or instruct the model to ignore embedded commands.\n
  • Capability inventory: The potential impact is minimal because the analysis scripts are constrained to reading files and printing to standard output. They do not perform network requests, write to the file system, or execute shell commands.\n
  • Sanitization: The input is processed as raw text without validation or sanitization against prompt injection techniques.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 02:18 AM
Security Audit — agent-trust-hub — docker-development