bubblewrap-isolation
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to execute commands inside a Bubblewrap (
bwrap) sandbox. While it facilitates command execution, it does so explicitly to provide defense-in-depth and isolation for the agent. The includedrun-isolated.shscript properly implements security best practices such as--unshare-all,--cap-drop ALL, and--clearenv. - [DATA_EXFILTRATION]: The configuration explicitly disables network access (
--unshare-allincluding the network namespace) and avoids binding host credential directories, effectively preventing data exfiltration from within the sandbox environment.
Audit Metadata