senior-devops
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface where instructions processed from a user's repository could influence agent behavior.
- Ingestion points: The
targetcommand-line argument inscripts/pipeline_generator.py,scripts/terraform_scaffolder.py, andscripts/deployment_manager.pydesignates external directories for processing. - Boundary markers: The provided script templates lack delimiters or specific instructions to ignore embedded prompts within the files they are intended to analyze.
- Capability inventory: While the provided scripts are currently skeletons, the
SKILL.mdinstructions guide the agent to perform sensitive operations likeaws ecs update-service,kubectl patch, andterraform applybased on the output of these tools. - Sanitization: No sanitization or validation logic is present in the boilerplate Python scripts to handle malicious content in the target paths.
- [METADATA_POISONING]: There is a discrepancy between the documented usage and the actual implementation of the scripts.
- Evidence:
SKILL.mddocumentation describes arguments like--platform,--stages, and--providerfor the scripts, but the provided source code inscripts/only implements basictarget,--verbose, and--jsonarguments. This inconsistency could lead an agent to attempt invalid command executions.
Audit Metadata