docker-expert
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes several shell commands to interact with the Docker environment and project files. These include informational commands like
docker infoanddocker ps, as well as build and validation commands likedocker build,docker run, anddocker execused on test containers for verification purposes. - [EXTERNAL_DOWNLOADS]: The skill performs Docker build and run operations which involve pulling container images from remote registries. These actions are standard for Docker-related tasks and the skill references well-known, trusted sources like Google's distroless images and official Alpine-based node images.
- [PROMPT_INJECTION]: The skill is subject to indirect prompt injection risk as it reads local configuration files to provide optimization advice.
- Ingestion points: The skill reads
Dockerfileanddocker-composefiles from the local filesystem during its initial analysis phase in SKILL.md. - Boundary markers: No specific boundary markers or instructions to ignore embedded commands within the analyzed files are present.
- Capability inventory: The skill can execute high-capability shell commands including
docker runanddocker execacross its validation workflows. - Sanitization: The skill does not sanitize or filter the content of the files it reads before processing them.
Audit Metadata