chatqna-docker-deploy

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the execution of shell commands, including docker, docker compose, and source, to manage container lifecycles and environment setup. These operations are aligned with the skill's primary objective of application deployment.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from user prompts—specifically image tags, registry paths, and configuration file locations—which are then interpolated into shell commands. While no specific injection payload was identified, this ingestion path combined with command execution capabilities represents an inherent attack surface. The instructions do not define explicit sanitization or boundary markers for these interpolated inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 01:43 PM
Security Audit — agent-trust-hub — chatqna-docker-deploy