vm-docker
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the download of Docker images from trusted and well-known registries, including GitHub Container Registry (ghcr.io), LinuxServer.io (lscr.io), and RedHat's Quay.io. These are standard sources for the specified applications.\n- [COMMAND_EXECUTION]: Provides a Makefile and shell command examples for managing container lifecycles using 'docker compose' and the 'crane' utility. These tools are used for their intended administrative purposes within the local VM environment.\n- [SAFE]: The skill includes reference configurations with clearly marked placeholders (e.g., '<POSTGRES_PASSWORD>', '<CMD_SESSION_SECRET>') and default credentials (e.g., 'changeme') intended for local initialization. The documentation explicitly instructs the user on how to generate secure secrets and manage them using environment files. Additionally, the infrastructure configuration uses standard security patterns, such as mounting the Docker socket in read-only mode for service discovery tools like Traefik and Homepage.
Audit Metadata