ops-docker
Fail
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script 'scripts/redeploy.sh' utilizes 'eval' to execute the content of the 'HEALTH_CMD' variable. This variable can be populated via the '--health-cmd' command-line argument or the 'HEALTH_CMD' environment variable, allowing for arbitrary command injection.
- [COMMAND_EXECUTION]: The 'run.sh' script sources a '.env' file from a directory structure dependent path ('$PROJECT_ROOT/.env'). This could result in the loading of untrusted environment variables if the skill is executed within a directory tree containing a malicious '.env' file.
- [REMOTE_CODE_EXECUTION]: The 'scripts/redeploy.sh' script executes 'docker compose pull', which initiates downloads of container images from external registries. These images contain executable entrypoints and layers from remote sources.
- [COMMAND_EXECUTION]: The 'scripts/prune.sh' script performs destructive Docker operations, including 'container prune', 'image prune', and 'volume prune' using the '--force' flag, which can lead to irreversible loss of containers and data volumes.
Recommendations
- AI detected serious security threats
Audit Metadata