devcontainer

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill generates configurations that reference base images and features from 'mcr.microsoft.com' and 'ghcr.io'. These are official and trusted sources for development container resources.\n- [DATA_EXPOSURE]: Scans project manifest files (such as package.json, pyproject.toml, and go.mod) and environment examples (.env.example) to detect the technology stack. It also records performance metadata locally in '~/.claude/projects/skill-telemetry.md' for session-based memory.\n- [PROMPT_INJECTION]: Contains instructions for 'AUTONOMOUS MODE' where the agent is told not to ask questions or pause for confirmation. This is a workflow optimization for automated generation tasks.\n- [PROMPT_INJECTION]: (Indirect) The skill has an indirect prompt injection surface as it reads untrusted project manifest files to populate templates. Ingestion points: project files like package.json (Phase 1). Boundary markers: absent. Capability inventory: file-write operations for .devcontainer files (Phase 2, 3). Sanitization: absent, relying on structured JSON/YAML generation to limit injection impact.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — devcontainer