bubblewrap-isolation

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to execute commands inside a Bubblewrap (bwrap) sandbox. While it facilitates command execution, it does so explicitly to provide defense-in-depth and isolation for the agent. The included run-isolated.sh script properly implements security best practices such as --unshare-all, --cap-drop ALL, and --clearenv.
  • [DATA_EXFILTRATION]: The configuration explicitly disables network access (--unshare-all including the network namespace) and avoids binding host credential directories, effectively preventing data exfiltration from within the sandbox environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:46 PM
Security Audit — agent-trust-hub — bubblewrap-isolation