managing-docker
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes Docker and Compose CLI tools to perform system discovery, resource monitoring, and configuration validation.
- [DATA_EXFILTRATION]: The skill interacts with the local Docker Unix socket to retrieve container information and inspects environment variables. It includes explicit warnings to prevent the accidental exposure of secrets found during these inspections.
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface (Category 8) because it ingests untrusted data from container logs and image metadata (Ingestion points: SKILL.md) and displays it to the agent without boundary markers or sanitization (Capability inventory: Docker CLI). This could potentially allow a malicious container to influence agent behavior through its output.
Audit Metadata