docker-patterns

Warn

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill includes eight large files (references/ref_guide_1.md through ref_guide_8.md) that are deceptively labeled as containing technical depth such as 'algorithms' and 'best practices.' In reality, they consist of 3,200 sections of trivial, repetitive Python code and identical YAML schemas with no technical utility. This misleading labeling disguises the true nature of the files.
  • [INDIRECT_PROMPT_INJECTION]: The massive volume of filler content (approx. 16,000 lines) serves as a context-stuffing vector. 1. Ingestion points: Files references/ref_guide_1.md to ref_guide_8.md enter the agent's context. 2. Boundary markers: Standard Markdown headers are used, providing no defense against context window exhaustion. 3. Capability inventory: The agent possesses capabilities for file system writes and subprocess execution across its operational files. 4. Sanitization: No filtering or validation of external filler data is implemented prior to context ingestion. This bloat exhausts the context window, which can be used to displace system instructions or hide malicious content from human auditors.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 1, 2026, 03:56 PM
Security Audit — agent-trust-hub — docker-patterns