docker-expert
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute various system and Docker CLI commands, including
docker build,docker info,docker ps, andfind. These commands are used to analyze the project structure and validate container configurations in the local environment.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to read and analyze untrusted project data (e.g.,Dockerfile,docker-compose.yml) which could contain malicious instructions meant to manipulate the agent's behavior.\n- Ingestion points: Processes content fromDockerfile*,*compose*.yml, and.dockerignorefiles within the working directory (SKILL.md).\n- Boundary markers: The skill does not implement specific delimiters or instructions to ignore or isolate embedded prompts within the analyzed files.\n- Capability inventory: The agent has the capability to execute shell commands, specifically within the Docker CLI ecosystem (docker build,docker run,docker exec) based on project configurations (SKILL.md).\n- Sanitization: No explicit sanitization or filtering of the content read from user-provided files is described in the skill.
Audit Metadata