Back to skill

Security audit

Docker Sandbox Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a Docker sandbox guide, but its activation scope is too broad for a tool that can run commands and use Docker.

Install only if you specifically want an agent to help create or run Docker-based sandboxes. Keep use user-directed, prefer no-network and resource-limited containers for untrusted code, and avoid letting this skill handle ordinary coding help or deployment tasks unless Docker sandboxing is explicitly needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description uses very broad activation phrasing such as code generation, programming assistance, debugging, testing, and deployment, which overlaps with a large fraction of normal developer requests. This can cause the agent to invoke a high-risk skill with exec/write capabilities in situations where a narrower, less privileged tool would be more appropriate, increasing the chance of unnecessary command execution or unsafe sandbox use.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The capability coverage section enumerates an expansive keyword list rather than strict invocation boundaries, including generic development terms that can match many unrelated prompts. In an agent ecosystem, this broad keyword targeting can bias routing toward a skill that exposes exec and write tools, creating avoidable privilege expansion and increasing the blast radius of prompt misclassification.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.