pgpm-docker

Warn

Audited by Gen Agent Trust Hub on Feb 27, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill interacts with the local system by invoking the pgpm CLI to start and stop Docker containers. This grants the agent the ability to manage system-level resources and processes.- [REMOTE_CODE_EXECUTION]: The skill documentation recommends running eval "$(pgpm env)" to set environment variables. This pattern executes the output of the CLI tool directly in the user's shell session, which can be leveraged for arbitrary code execution if the tool provides malicious output.- [EXTERNAL_DOWNLOADS]: The skill is configured to pull and run the pyramation/postgres:17 Docker image. This image originates from a third-party repository that is not part of the established trusted vendor list.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 27, 2026, 05:14 AM