cloud-security-audit

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious behavior or technical vulnerabilities were identified. The skill is purely instructional, defining the tasks and output formats for a cloud security assessment specialist.
  • [PROMPT_INJECTION]: The skill is designed to audit cloud configurations and codebases using the codebase and filesystem tools, which constitutes an indirect prompt injection surface. This means the agent could be influenced by malicious instructions found within the files it is asked to audit.
  • Ingestion points: Untrusted data enters the agent context via the codebase and filesystem tools as specified in the frontmatter of SKILL.md.
  • Boundary markers: Absent; there are no specific delimiters or instructions to ignore embedded commands in the audited data.
  • Capability inventory: The skill uses codebase and filesystem tools; no specific network or file-write operations are scripted in this file.
  • Sanitization: No evidence of sanitization or filtering of external configuration data was found in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 11:03 AM
Security Audit — agent-trust-hub — cloud-security-audit