sre-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous Python scripts that utilize
subprocess.runto interact with system and cluster management tools. This includes usingkubectlfor Kubernetes operations,systemctlfor service management, and networking tools liketcandiptablesfor chaos engineering experiments.\n- [DYNAMIC_EXECUTION]: TheAutomatedRunbookimplementation inreferences/automation-toil.mdusessubprocess.run(shell=True)to execute command strings. This facilitates the automation of operational tasks but introduces a risk if commands are derived from untrusted inputs.\n- [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves the agent querying and processing data from external monitoring sources such as Prometheus. This creates a surface for indirect prompt injection if the monitoring data contains malicious instructions.\n - Ingestion points: Prometheus API queries defined in
SKILL.mdandreferences/monitoring-alerting.md.\n - Boundary markers: None explicitly implemented to separate data from instructions in the provided templates.\n
- Capability inventory: The skill possesses significant capabilities, including arbitrary shell command execution and Kubernetes cluster management.\n
- Sanitization: The provided Python templates do not include explicit sanitization or validation of the data retrieved from external monitoring endpoints.
Audit Metadata