playbook-configuration

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides templates and instructions for executing system commands through Ansible, specifically targeting cluster management tools like kubectl and helm.
  • Evidence: Guidance on using ansible.builtin.command and become: true for administrative tasks in SKILL.md.
  • Mitigation: The skill explicitly requires setting requires_approval: true for any task using become, changing host/cluster state, or installing packages.
  • [PROMPT_INJECTION]: As the skill is designed to review, edit, and explain external files (Ansible playbooks), it possesses an attack surface for indirect prompt injection where malicious instructions embedded in a playbook could attempt to influence agent behavior.
  • Ingestion points: Playbooks located in the ansible/playbooks directory as specified in the SKILL.md frontmatter.
  • Boundary markers: The instructions do not define specific delimiters or "ignore instructions" blocks for the ingested playbook content.
  • Capability inventory: The skill utilizes subprocess calls via Ansible, privilege escalation (become), and file-write operations.
  • Sanitization: No explicit sanitization or validation of the ingested playbook content is performed beyond the internal logic of the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 10:05 AM
Security Audit — agent-trust-hub — playbook-configuration