container-security
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill processes local file paths provided as arguments to perform configuration audits. It uses standard file reading operations and does not execute shell commands or interact with external processes.
- [DYNAMIC_EXECUTION]: Employs dynamic module loading using
__import__('yaml')to provide optional support for YAML configuration files. This implementation is benign as it is used specifically to access theyaml.safe_loadfunction, which prevents arbitrary code execution during parsing. - [DATA_EXPOSURE]: Includes a dedicated security check (CTR-2.1) designed to detect and report hardcoded secrets in container environment variables, improving the security posture of the audited assets.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted configuration data (JSON/YAML). Analysis shows that this data is parsed into structured objects and processed through static logic and regular expressions. There are no exploitable capabilities such as code execution or network requests that could be triggered by malicious instructions within the audited files.
Audit Metadata