governing-sbx-fleets

Warn

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill includes instructions for deploying sign-in enforcement that require administrative or root access to the target host.\n
  • Linux: The deployment guide in references/sign-in-enforcement-deploy.md uses sudo to write configuration to /etc/docker-sbx/config.json.\n
  • Windows: The deployment guide in references/sign-in-enforcement-deploy.md uses registry paths in HKLM (HKEY_LOCAL_MACHINE), which requires elevated privileges.\n
  • macOS: Mentions using MDM-deployed configuration profiles for policy enforcement, which operate at a system level.\n- [COMMAND_EXECUTION]: The skill provides various administrative commands for local policy management and system configuration.\n
  • Commands include sbx policy reset and sbx reset, which terminate running sandboxes and modify daemon states.\n
  • The skill documents usage of defaults write (macOS) and New-ItemProperty (Windows) to enforce security settings.\n- [INDIRECT_PROMPT_INJECTION]: The skill manages sandbox governance through external policies, creating an attack surface for indirect prompt injection.\n
  • Ingestion points: Policies fetched from the Governance API or Docker Home (SKILL.md).\n
  • Boundary markers: Absent.\n
  • Capability inventory: Filesystem mount access, network egress control, and audit logging configuration.\n
  • Sanitization: Absent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 24, 2026, 04:44 PM
Security Audit — agent-trust-hub — governing-sbx-fleets