harbor-expert

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external container registries and vulnerability scanners which could theoretically contain malicious instructions.
  • Ingestion points: Multiple scripts in SKILL.md and the references/ directory (e.g., monitor-replication.py, bulk-scan.py, webhook-processor.py) ingest JSON responses from Harbor API endpoints.
  • Capability inventory: The skill can perform network operations to third-party services (AWS Route53, Slack, Jira, Docker Hub), manage registry artifacts, and create/rotate robot accounts and projects.
  • Boundary markers: Data processing scripts lack explicit boundary markers or instructions to ignore embedded content within the ingested JSON data.
  • Sanitization: The skill primarily uses jq and standard language-level JSON parsers to handle external data, which provides basic structural validation.
  • [COMMAND_EXECUTION]: The skill provides numerous shell and Python utilities for registry automation. This includes the use of curl for API interactions and aws CLI for managing DNS records during disaster recovery (documented in references/replication-guide.md). These capabilities are intrinsic to the skill's purpose as an infrastructure administration tool.
  • [CREDENTIALS_UNSAFE]: Documentation examples frequently use the string admin:password in curl command templates. While conventionally recognized as a placeholder in technical guides, it represents a hardcoded credential pattern. The skill balances this by also demonstrating best practices, such as the use of environment variables and GitHub Action secrets for sensitive token management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 05:23 PM
Security Audit — agent-trust-hub — harbor-expert