devops-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous templates and scripts for executing shell commands, including
kubectl,docker,terraform, andgit, which are necessary for its primary function as a DevOps automation tool. - [EXTERNAL_DOWNLOADS]: The skill references standard tools and libraries from well-known sources, such as GitHub Actions, Python packages like
kubernetesandfastapi, and container images from official registries. - [DATA_EXFILTRATION]: The skill includes network operations via
curlandwgetfor health checks and interacting with internal platform APIs, which are appropriate for its intended use case. - [INDIRECT_PROMPT_INJECTION]: Ingestion points: The skill processes user-provided Dockerfiles and Kubernetes manifests in
references/docker-patterns.mdandreferences/kubernetes.md. Boundary markers: Includes validation steps liketerraform plan. Capability inventory: Extensive capabilities includingkubectl,docker, and cloud CLI execution. Sanitization: Recommends container scanning and strict secret management to mitigate injection risks. - [DYNAMIC_EXECUTION]: The skill includes automation scripts and Python-based remediation logic that dynamically generate configurations or interact with APIs to manage environment state as part of its core DevOps workflow.
Audit Metadata