docker-scout

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional documentation, CLI command examples, and YAML configuration snippets for CI/CD workflows. No executable scripts or binary files are included.
  • [EXTERNAL_DOWNLOADS]: The skill references official GitHub Actions from Docker (docker/scout-action) and GitHub (actions/checkout, github/codeql-action). These are well-known, trusted services used for standard development workflows.
  • [PROMPT_INJECTION]: There are no patterns suggesting attempts to override agent behavior, bypass safety filters, or extract system prompts. The instructional language is standard for technical documentation.
  • [COMMAND_EXECUTION]: While the skill provides many shell command examples, these are intended for the user to execute in their local environment or CI/CD pipelines as part of legitimate security scanning procedures.
  • [DATA_EXFILTRATION]: No evidence of hardcoded credentials, sensitive file path access, or unauthorized network operations was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 10:25 AM
Security Audit — agent-trust-hub — docker-scout