docker
Fail
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a
rawtool that allows the execution of arbitrary Docker commands. Because access to the Docker daemon is often equivalent to root privileges on the host, this presents a significant security risk despite basic validation attempts. - [COMMAND_EXECUTION]: Shell commands are constructed by joining argument arrays with spaces without escaping shell metacharacters (e.g.,
;,&,|,`,$()). An attacker could inject additional host commands by including these characters in parameters likeimage,container, orcommand. - [DATA_EXFILTRATION]: The
logs,exec, andinspecttools provide capabilities to extract sensitive data from running containers, such as environment variables containing credentials, private configuration files, or database contents. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from container logs and inspection results, which could be used to deliver malicious instructions to the agent (Indirect Prompt Injection).
- Ingestion points: Data retrieved via
docker logs,docker ps, anddocker inspect(skill.js). - Boundary markers: None identified; output is returned directly as a string.
- Capability inventory: Full Docker CLI access, which includes file system modification and network operations.
- Sanitization: No filtering or escaping is applied to container-generated output before returning it to the agent context.
Recommendations
- AI detected serious security threats
Audit Metadata