docker-expert

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes various shell commands (e.g., docker info, docker ps, find) to discover the local Docker environment and project structure.
  • [COMMAND_EXECUTION]: The skill performs active validation by building (docker build) and running (docker run) containers based on local project files. These operations are performed locally and are aligned with the tool's primary purpose.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it automatically locates and processes local configuration files (Dockerfiles, Compose files). If these files contain malicious instructions, the agent might inadvertently execute them during the build or run validation phases. Evidence Chain: 1. Ingestion points: Discovery of local files via find . -name "Dockerfile*". 2. Boundary markers: Not explicitly defined in the instructions. 3. Capability inventory: Significant local capabilities including docker build, docker run, and docker exec. 4. Sanitization: No specific sanitization or validation of the Dockerfile content is described before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 08:28 PM
Security Audit — agent-trust-hub — docker-expert