docker-scout
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of instructional documentation, CLI command examples, and YAML configuration snippets for CI/CD workflows. No executable scripts or binary files are included.
- [EXTERNAL_DOWNLOADS]: The skill references official GitHub Actions from Docker (
docker/scout-action) and GitHub (actions/checkout,github/codeql-action). These are well-known, trusted services used for standard development workflows. - [PROMPT_INJECTION]: There are no patterns suggesting attempts to override agent behavior, bypass safety filters, or extract system prompts. The instructional language is standard for technical documentation.
- [COMMAND_EXECUTION]: While the skill provides many shell command examples, these are intended for the user to execute in their local environment or CI/CD pipelines as part of legitimate security scanning procedures.
- [DATA_EXFILTRATION]: No evidence of hardcoded credentials, sensitive file path access, or unauthorized network operations was found.
Audit Metadata