infra-container-build-review
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides guidelines for auditing infrastructure containers and explicitly recommends defensive configurations, such as pinning base image digests and dropping all Linux capabilities. It warns against executing unverified scripts via curl during the build process.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Dockerfiles, deployment manifests, and system logs. While no boundary markers or sanitization logic are defined, the skill does not expose any high-risk capabilities like subprocess execution or network writes, thus keeping the risk at a safe level for a review-oriented agent.
Audit Metadata