governing-sbx-fleets
Warn
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill includes instructions for deploying sign-in enforcement that require administrative or root access to the target host.\n
- Linux: The deployment guide in
references/sign-in-enforcement-deploy.mdusessudoto write configuration to/etc/docker-sbx/config.json.\n - Windows: The deployment guide in
references/sign-in-enforcement-deploy.mduses registry paths inHKLM(HKEY_LOCAL_MACHINE), which requires elevated privileges.\n - macOS: Mentions using MDM-deployed configuration profiles for policy enforcement, which operate at a system level.\n- [COMMAND_EXECUTION]: The skill provides various administrative commands for local policy management and system configuration.\n
- Commands include
sbx policy resetandsbx reset, which terminate running sandboxes and modify daemon states.\n - The skill documents usage of
defaults write(macOS) andNew-ItemProperty(Windows) to enforce security settings.\n- [INDIRECT_PROMPT_INJECTION]: The skill manages sandbox governance through external policies, creating an attack surface for indirect prompt injection.\n - Ingestion points: Policies fetched from the Governance API or Docker Home (SKILL.md).\n
- Boundary markers: Absent.\n
- Capability inventory: Filesystem mount access, network egress control, and audit logging configuration.\n
- Sanitization: Absent.
Audit Metadata