docker
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides robust security guidelines for containerization, mandating practices such as multi-stage builds, non-root runtime environments, and base image pinning. These invariants are designed to minimize attack surfaces and ensure image reproducibility.\n- [EXTERNAL_DOWNLOADS]: The reference materials include examples using well-known and official resources, such as images from Docker Hub, ECR, and GHCR, as well as security scanning tools like Aqua Security's Trivy. These are documented as industry-standard practices for secure development and CI/CD pipelines.\n- [INDIRECT_PROMPT_INJECTION]: The skill accepts user-provided Docker tasks. It mitigates potential risks from untrusted data by requiring the agent to follow a strict 'stack contract' and established security guardrails, ensuring that generated configurations remain within safe boundaries.
Audit Metadata