dockerfile-gen

Warn

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to run npx ai-dockerfile, which downloads and executes code from the npm registry at runtime. Since this package originates from a third-party entity ('LXGIC Studios') and not a verified or trusted vendor, it presents a risk of arbitrary code execution on the user's system.\n- [PROMPT_INJECTION]: The skill performs project scanning to detect technology stacks, which constitutes a surface for indirect prompt injection. Malicious content within the scanned project files could be used to manipulate the agent's behavior or the configuration it generates. 1. Ingestion points: Local project files scanned by the tool. 2. Boundary markers: None described in the skill instructions. 3. Capability inventory: Execution of shell commands via npx. 4. Sanitization: No sanitization or validation of the scanned content is mentioned.\n- [COMMAND_EXECUTION]: The skill provides the agent with direct shell commands (npx ai-dockerfile) that interact with the host environment and network resources.\n- [EXTERNAL_DOWNLOADS]: The use of npx requires the agent to fetch external code from the public npm registry during execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 7, 2026, 11:33 AM
Security Audit — agent-trust-hub — dockerfile-gen