docker
Fail
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: Installation scripts download and execute the official Docker convenience script from https://get.docker.com. This is a standard procedure for setting up Docker Engine on Linux.
- [CREDENTIALS_UNSAFE]: The compose-web-db template includes hardcoded default database credentials (postgres/postgres) in its configuration. These are intended for development and should be modified for production use.
- [EXTERNAL_DOWNLOADS]: The skill fetches installation assets from official Docker domains and references images from Docker Hub.
- [INDIRECT_PROMPT_INJECTION]: The skill parses container logs and configuration files, which could potentially contain malicious instructions from an external source.
- [PRIVILEGE_ESCALATION]: Setup routines utilize sudo for system-level configuration and user group management.
- [COMMAND_EXECUTION]: Automated diagnostic scripts (probe-docker.ps1 and doctor-docker.ps1) execute various Docker CLI commands to verify environment state.
Recommendations
- HIGH: Downloads and executes remote code from: https://get.docker.com - DO NOT USE without thorough review
Audit Metadata