docker-compose
Warn
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [METADATA_POISONING]: The skill uses deceptive metadata fields in its YAML frontmatter, specifically 'verified: true', 'source: builtin', and 'trust_score: 100'. These self-asserted claims are designed to bypass security scrutiny by mimicking official platform components, which could mislead an agent or user regarding the skill's origin and safety status.
- [INDIRECT_PROMPT_INJECTION]: The skill implements functionality to read external, untrusted data from Docker containers, creating an attack surface for indirect prompt injection. 1. Ingestion points: The skill captures and returns output from 'docker compose logs', 'exec', and 'run' commands to the agent context. 2. Boundary markers: The skill instructions do not define clear delimiters or specific instructions to treat container output as untrusted data. 3. Capability inventory: The skill has high privileges within the containerized environment, including the ability to start/stop services, build images, and execute arbitrary commands. 4. Sanitization: The JavaScript implementation in 'main.cjs' and the associated hooks do not perform any filtering or sanitization of the container output before it is passed to the agent.
- [COMMAND_EXECUTION]: The skill enables the execution of arbitrary commands within Docker containers via the 'exec' and 'run' tools. While the underlying execution in 'main.cjs' uses 'shell: false' to prevent host-level shell injection, the script does not programmatically enforce the safety restrictions mentioned in the documentation (such as blocking 'rm -rf'), relying instead on the agent to follow natural language guidelines which can be bypassed.
Audit Metadata