security-container-security
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions and examples for downloading security tools and scanning databases from the official GitHub repositories of well-known vendors, including Aqua Security and Anchore.
- [REMOTE_CODE_EXECUTION]: Reference documents include installation examples that use the piped shell pattern (
curl | sh). These examples are sourced from verified technology providers and are intended for the installation of legitimate security utilities. - [COMMAND_EXECUTION]: The skill generates configurations for CI/CD pipelines and operational tasks that execute shell commands for container image building, vulnerability scanning, and signature verification.
- [SAFE]: Multiple reference files (e.g., architecture-patterns.md, state-management.md) contain extensive sections of repetitive technical text. This behavior appears to be a case of technical bloat or poor document generation rather than a mechanism for hiding malicious payloads or obfuscated instructions.
Audit Metadata