skills/alvindean/soniq/senior-devops/Gen Agent Trust Hub

senior-devops

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface where instructions processed from a user's repository could influence agent behavior.
  • Ingestion points: The target command-line argument in scripts/pipeline_generator.py, scripts/terraform_scaffolder.py, and scripts/deployment_manager.py designates external directories for processing.
  • Boundary markers: The provided script templates lack delimiters or specific instructions to ignore embedded prompts within the files they are intended to analyze.
  • Capability inventory: While the provided scripts are currently skeletons, the SKILL.md instructions guide the agent to perform sensitive operations like aws ecs update-service, kubectl patch, and terraform apply based on the output of these tools.
  • Sanitization: No sanitization or validation logic is present in the boilerplate Python scripts to handle malicious content in the target paths.
  • [METADATA_POISONING]: There is a discrepancy between the documented usage and the actual implementation of the scripts.
  • Evidence: SKILL.md documentation describes arguments like --platform, --stages, and --provider for the scripts, but the provided source code in scripts/ only implements basic target, --verbose, and --json arguments. This inconsistency could lead an agent to attempt invalid command executions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:33 PM