skills/v1truv1us/ai-eng-system/docker/Gen Agent Trust Hub

docker

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents standard Docker CLI and security scanning commands (e.g., docker scout, trivy, snyk) intended for local or CI/CD execution by the user or an agent. These are routine development operations.
  • [EXTERNAL_DOWNLOADS]: The skill provides links to official Docker documentation and references official container images from Docker Hub (e.g., node:22-alpine). These are well-known and trusted resources.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides templates and checklists for reviewing Dockerfiles and Compose files. While it processes configuration data, it maintains clear boundaries and does not possess capabilities that could be exploited via malicious input in a way that compromises the host environment.
  • [SAFE]: The Dockerfile and Docker Compose examples follow industry security best practices, such as using multi-stage builds, non-root users, and health checks. Instructions explicitly advise against anti-patterns like hardcoding secrets in environment variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 11:52 AM
Security Audit — agent-trust-hub — docker