cloud-security-audit
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious behavior or technical vulnerabilities were identified. The skill is purely instructional, defining the tasks and output formats for a cloud security assessment specialist.
- [PROMPT_INJECTION]: The skill is designed to audit cloud configurations and codebases using the
codebaseandfilesystemtools, which constitutes an indirect prompt injection surface. This means the agent could be influenced by malicious instructions found within the files it is asked to audit. - Ingestion points: Untrusted data enters the agent context via the
codebaseandfilesystemtools as specified in the frontmatter of SKILL.md. - Boundary markers: Absent; there are no specific delimiters or instructions to ignore embedded commands in the audited data.
- Capability inventory: The skill uses
codebaseandfilesystemtools; no specific network or file-write operations are scripted in this file. - Sanitization: No evidence of sanitization or filtering of external configuration data was found in the instructions.
Audit Metadata