harbor-expert
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external container registries and vulnerability scanners which could theoretically contain malicious instructions.
- Ingestion points: Multiple scripts in
SKILL.mdand thereferences/directory (e.g.,monitor-replication.py,bulk-scan.py,webhook-processor.py) ingest JSON responses from Harbor API endpoints. - Capability inventory: The skill can perform network operations to third-party services (AWS Route53, Slack, Jira, Docker Hub), manage registry artifacts, and create/rotate robot accounts and projects.
- Boundary markers: Data processing scripts lack explicit boundary markers or instructions to ignore embedded content within the ingested JSON data.
- Sanitization: The skill primarily uses
jqand standard language-level JSON parsers to handle external data, which provides basic structural validation. - [COMMAND_EXECUTION]: The skill provides numerous shell and Python utilities for registry automation. This includes the use of
curlfor API interactions andawsCLI for managing DNS records during disaster recovery (documented inreferences/replication-guide.md). These capabilities are intrinsic to the skill's purpose as an infrastructure administration tool. - [CREDENTIALS_UNSAFE]: Documentation examples frequently use the string
admin:passwordincurlcommand templates. While conventionally recognized as a placeholder in technical guides, it represents a hardcoded credential pattern. The skill balances this by also demonstrating best practices, such as the use of environment variables and GitHub Action secrets for sensitive token management.
Audit Metadata