docker
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill instructions explicitly utilize
sudoto start the Docker daemon (sudo dockerd) and run containers (sudo docker run), which grants the agent administrative privileges on the host system. - [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for executing Docker commands which can be influenced by untrusted user input. 1. Ingestion points: User-provided instructions trigger Docker commands in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: System-level command execution via
sudo. 4. Sanitization: Absent. - [COMMAND_EXECUTION]: The skill is designed to execute powerful shell commands such as
dockerdanddocker rundirectly on the host or container environment.
Audit Metadata