plugin-docker-compose

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @diagrams-js/plugin-docker-compose package from the NPM registry. This package is part of the official ecosystem for the diagrams-js library authored by hatemhosny.
  • [EXTERNAL_DOWNLOADS]: The plugin supports fetching icons from external sources including the Iconify API (icon-sets.iconify.design) and user-defined URLs. These are standard features for architectural diagramming tools to provide visual assets.
  • [DATA_EXFILTRATION]: While Docker Compose files can contain environment variables and secrets, the skill functions as a local transformation library. There are no instructions or code patterns that attempt to exfiltrate this data to unauthorized remote servers.
  • [PROMPT_INJECTION]: The instructions are purely technical and do not contain any attempts to override the AI agent's safety protocols or system instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 01:02 AM
Security Audit — agent-trust-hub — plugin-docker-compose