doorman
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed around the
doormanCLI tool, instructing the agent to execute shell commands for syncing, validating, and deploying firewall configurations. - [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@gfargo/doormanpackage from the NPM registry. This resource is managed by the skill's author ('gfargo') and represents the core functionality of the skill. - [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to ingest external configuration files and live firewall rules from cloud provider APIs.
- Ingestion points: Processes
.doorman.jsonconfiguration files and fetches remote data via thedoorman downloadcommand. - Boundary markers: The skill uses structured JSON schemas for configuration, which provides a layer of data validation.
- Capability inventory: The skill has the ability to execute the
doormanCLI, which can modify WAF rules on remote providers and manage local filesystem backups. - Sanitization: The instructions mandate the use of
doorman validateto verify configuration integrity anddoorman diffto preview changes before synchronization, reducing the risk of unintended modifications from untrusted data.
Audit Metadata