skills/gfargo/skills/doorman/Gen Agent Trust Hub

doorman

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed around the doorman CLI tool, instructing the agent to execute shell commands for syncing, validating, and deploying firewall configurations.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @gfargo/doorman package from the NPM registry. This resource is managed by the skill's author ('gfargo') and represents the core functionality of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to ingest external configuration files and live firewall rules from cloud provider APIs.
  • Ingestion points: Processes .doorman.json configuration files and fetches remote data via the doorman download command.
  • Boundary markers: The skill uses structured JSON schemas for configuration, which provides a layer of data validation.
  • Capability inventory: The skill has the ability to execute the doorman CLI, which can modify WAF rules on remote providers and manage local filesystem backups.
  • Sanitization: The instructions mandate the use of doorman validate to verify configuration integrity and doorman diff to preview changes before synchronization, reducing the risk of unintended modifications from untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 04:41 PM
Security Audit — agent-trust-hub — doorman