devcontainer
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill generates configurations that reference base images and features from 'mcr.microsoft.com' and 'ghcr.io'. These are official and trusted sources for development container resources.\n- [DATA_EXPOSURE]: Scans project manifest files (such as package.json, pyproject.toml, and go.mod) and environment examples (.env.example) to detect the technology stack. It also records performance metadata locally in '~/.claude/projects/skill-telemetry.md' for session-based memory.\n- [PROMPT_INJECTION]: Contains instructions for 'AUTONOMOUS MODE' where the agent is told not to ask questions or pause for confirmation. This is a workflow optimization for automated generation tasks.\n- [PROMPT_INJECTION]: (Indirect) The skill has an indirect prompt injection surface as it reads untrusted project manifest files to populate templates. Ingestion points: project files like package.json (Phase 1). Boundary markers: absent. Capability inventory: file-write operations for .devcontainer files (Phase 2, 3). Sanitization: absent, relying on structured JSON/YAML generation to limit injection impact.
Audit Metadata