docker-expert
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes various shell commands (e.g.,
docker info,docker ps,find) to discover the local Docker environment and project structure. - [COMMAND_EXECUTION]: The skill performs active validation by building (
docker build) and running (docker run) containers based on local project files. These operations are performed locally and are aligned with the tool's primary purpose. - [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it automatically locates and processes local configuration files (Dockerfiles, Compose files). If these files contain malicious instructions, the agent might inadvertently execute them during the build or run validation phases. Evidence Chain: 1. Ingestion points: Discovery of local files via
find . -name "Dockerfile*". 2. Boundary markers: Not explicitly defined in the instructions. 3. Capability inventory: Significant local capabilities includingdocker build,docker run, anddocker exec. 4. Sanitization: No specific sanitization or validation of the Dockerfile content is described before execution.
Audit Metadata