docker-expert

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes host-level shell commands including docker build, docker run, and docker exec to validate local container configurations. These are standard operations for a Docker optimization and troubleshooting tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect injection as it analyzes and builds files from the local project environment.
  • Ingestion points: Local filesystem via file discovery tools, specifically targeting Dockerfile and docker-compose.yml files.
  • Boundary markers: None identified; the skill processes local files as authoritative configurations.
  • Capability inventory: Host-level execution of docker build, docker run, and docker-compose config which interpret and execute instructions contained within the local files.
  • Sanitization: None; the skill assumes the local project files are intended for building and execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — docker-expert