skills/openhands/extensions/docker/Gen Agent Trust Hub

docker

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill instructions explicitly utilize sudo to start the Docker daemon (sudo dockerd) and run containers (sudo docker run), which grants the agent administrative privileges on the host system.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for executing Docker commands which can be influenced by untrusted user input. 1. Ingestion points: User-provided instructions trigger Docker commands in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: System-level command execution via sudo. 4. Sanitization: Absent.
  • [COMMAND_EXECUTION]: The skill is designed to execute powerful shell commands such as dockerd and docker run directly on the host or container environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 04:50 PM
Security Audit — agent-trust-hub — docker