containerize-aspnetcore
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill's 'Containerization Settings' section explicitly prompts the user to 'List any private NuGet feeds with authentication details'. This encourages the handling and potential hardcoding of sensitive credentials within configuration files or the agent's prompt context, rather than using secure secret management practices.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, potentially untrusted project files and user settings to drive its execution logic.
- Ingestion points: The agent reads settings defined in
SKILL.mdand metadata from project files such as.csprojandNuGet.config. - Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the ingested project files.
- Capability inventory: The skill performs file writes (Dockerfile, .dockerignore) and executes shell commands (
docker build,dotnet restore). - Sanitization: The instructions lack validation or sanitization of the input settings before they are interpolated into the generated Dockerfile or used in shell commands.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands, specifically
docker build -t aspnetcore-app:latest .. While this is necessary for the skill's primary function, it provides a vector where malicious instructions embedded in project files could be executed during the image build process.
Audit Metadata