vm-template-creation
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill manages virtual infrastructure and ingests user-supplied configurations, creating an attack surface for indirect prompt injection. Ingestion points: User-provided VM IDs, node names, and VM names in tool-call examples. Boundary markers: No delimiters or safety instructions are present to prevent the agent from obeying instructions embedded in configuration data. Capability inventory: Includes tools for VM creation, configuration update, cloning, and deletion (e.g., delete_vm, create_vm_advanced). Sanitization: No input sanitization or validation logic is documented.
- [INDIRECT_PROMPT_INJECTION]: The skill contains self-referential safety claims in output.json and skill-report.json. These files include pre-authored security audits stating 'risk_level: safe', which attempts to override the analyzer's independent evaluation.
- [METADATA_POISONING]: The skill includes a pre-generated audit report (skill-report.json) that classifies its own potential issues as false positives, which is a deceptive metadata practice.
Audit Metadata