docker-expert
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes host-level shell commands including
docker build,docker run, anddocker execto validate local container configurations. These are standard operations for a Docker optimization and troubleshooting tool. - [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect injection as it analyzes and builds files from the local project environment.
- Ingestion points: Local filesystem via file discovery tools, specifically targeting
Dockerfileanddocker-compose.ymlfiles. - Boundary markers: None identified; the skill processes local files as authoritative configurations.
- Capability inventory: Host-level execution of
docker build,docker run, anddocker-compose configwhich interpret and execute instructions contained within the local files. - Sanitization: None; the skill assumes the local project files are intended for building and execution.
Audit Metadata