infra-container-runtime-review

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is configured to ingest and process a wide variety of external infrastructure data, creating a potential surface for indirect prompt injection where instructions could be hidden in analyzed content.
  • Ingestion points: As specified in the 'Evidence' section of SKILL.md, the agent ingests job specs, Dockerfiles, proxy configurations, deployment manifests, and system logs.
  • Boundary markers: The instructions lack explicit boundary markers or directions for the agent to treat external content as data only and ignore any embedded instructions.
  • Capability inventory: The agent performs deep inspection of container state, resource allocations, and operational diagnostics as described in the 'Process' section of SKILL.md.
  • Sanitization: The skill does not specify any sanitization, filtering, or validation steps for the content retrieved from the analyzed files or log streams.
  • [SAFE]: The skill promotes significant security hardening practices in references/01-overview.md, such as enforcing non-root users, dropping kernel capabilities (cap_drop), and utilizing read-only filesystems in container configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:31 PM
Security Audit — agent-trust-hub — infra-container-runtime-review