docker-orchestrator
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes and processes user-provided configuration files such as Dockerfiles, docker-compose.yml, and project source code. This creates an attack surface where malicious instructions embedded in project comments or metadata could influence the agent's output during optimization or generation tasks.
- Ingestion points: The agent reads user-provided
Dockerfile,docker-compose.yml,package.json, andpyproject.tomlfiles from the working directory (references inSKILL.mdandreferences/dockerfile.md). - Boundary markers: No explicit instructions or delimiters are used to differentiate between the agent's system instructions and untrusted content within the files being processed.
- Capability inventory: The skill assists in generating and executing Docker commands and orchestrating container environments (referenced in
SKILL.md). - Sanitization: There is no evidence of sanitization or validation performed on the user-provided files before they are processed by the agent.
Audit Metadata