detecting-container-escape-attempts

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches configuration and Helm charts from the official Falcosecurity GitHub/Helm repository, which is a well-known service and a Cloud Native Computing Foundation (CNCF) project.
  • [COMMAND_EXECUTION]: Includes standard Linux commands for deploying security monitoring tools (Helm, kubectl) and inspecting system logs (ausearch, docker inspect) to validate detection rules.
  • [SAFE]: No sensitive data exposure or exfiltration patterns were detected; credential fields for Slack and PagerDuty use placeholders (xxx), which is a safe practice.
  • [SAFE]: The skill explicitly includes a 'Red Flags' section emphasizing the importance of authorization, scope boundaries, and rules of engagement, aligning with security professional standards.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 03:39 PM
Security Audit — agent-trust-hub — detecting-container-escape-attempts