docker-expert

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to inspect the local Docker environment and validate configurations. Actions include running docker info, docker ps, find to locate project files, and docker build to test Dockerfiles. These operations are restricted to the local environment and are necessary for the skill's stated purpose as a DevOps tool.
  • [EXTERNAL_DOWNLOADS]: The skill references container images and configurations from well-known and trusted services. Specifically, it uses official Docker Hub images (e.g., node:18-alpine, postgres:15-alpine) and Google Container Registry images (gcr.io/distroless/nodejs18-debian11). These references follow industry standards for base image selection.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it is designed to read and analyze local project files, such as Dockerfile and compose.yml, which could contain malicious instructions.
  • Ingestion points: The skill uses find and file-reading tools to locate and analyze existing configuration files (SKILL.md).
  • Boundary markers: No specific boundary markers or "ignore embedded instructions" warnings are used when reading these files.
  • Capability inventory: The skill can execute shell commands (docker build, docker run, docker exec) based on the analysis of these files.
  • Sanitization: There is no explicit sanitization of the content read from local files before it is processed by the agent.
  • Risk Factor: The vulnerability is limited to the local file system and is part of the intended functionality for a development tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:18 AM
Security Audit — agent-trust-hub — docker-expert