docker-production

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The file references/03-monitoring-setup.md includes a hardcoded default password 'admin' for the Grafana service via the GF_SECURITY_ADMIN_PASSWORD environment variable.
  • [COMMAND_EXECUTION]: The monitoring configuration in references/03-monitoring-setup.md grants 'privileged: true' status to the cadvisor service and mounts sensitive host paths including the root filesystem ('/') and the Docker daemon socket ('/var/run/docker.sock'), which are high-privilege operations standard for monitoring but requiring caution in production.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 04:13 AM
Security Audit — agent-trust-hub — docker-production