sc-iac
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill instructions and metadata do not contain any malicious patterns, credentials, or dangerous command executions.- [PROMPT_INJECTION]: The skill includes instructions to process untrusted IaC configuration files (Dockerfile, Terraform, K8s, GitHub Actions). This creates a surface for indirect prompt injection, though the skill provides no execution capabilities that could be exploited.
- Ingestion points: Dockerfiles, Terraform scripts, Kubernetes manifests, and workflow files specified in Phase 1 (SKILL.md).
- Boundary markers: None specified in the instructions.
- Capability inventory: No executable scripts or high-privilege tools are included in the skill package.
- Sanitization: No input validation or escaping procedures are defined.
Audit Metadata