skills/ericrisco/rsc-harness/docker/Gen Agent Trust Hub

docker

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive guidance on Docker security best practices, including using non-root users, multi-stage builds to reduce attack surface, and using BuildKit secrets to avoid leaking credentials in image layers.
  • [COMMAND_EXECUTION]: The scripts/verify.sh file executes local system commands (grep, hadolint, docker, trivy, dockle) to perform static analysis and linting of Docker artifacts. These operations are read-only, limited to the local environment, and intended for security verification.
  • [EXTERNAL_DOWNLOADS]: The skill references several official and well-known Docker images from trusted sources, including Docker Hub, Google Container Registry (distroless), and GitHub Container Registry (Chainguard/Wolfi and Astral-sh/uv). These are standard references for container development.
  • [PROMPT_INJECTION]: No prompt injection patterns were detected. The instructions are focused on providing technical guidance and do not attempt to override agent safety filters or system prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:36 PM
Security Audit — agent-trust-hub — docker