playbook-configuration
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides templates and instructions for executing system commands through Ansible, specifically targeting cluster management tools like
kubectlandhelm. - Evidence: Guidance on using
ansible.builtin.commandandbecome: truefor administrative tasks inSKILL.md. - Mitigation: The skill explicitly requires setting
requires_approval: truefor any task usingbecome, changing host/cluster state, or installing packages. - [PROMPT_INJECTION]: As the skill is designed to review, edit, and explain external files (Ansible playbooks), it possesses an attack surface for indirect prompt injection where malicious instructions embedded in a playbook could attempt to influence agent behavior.
- Ingestion points: Playbooks located in the
ansible/playbooksdirectory as specified in theSKILL.mdfrontmatter. - Boundary markers: The instructions do not define specific delimiters or "ignore instructions" blocks for the ingested playbook content.
- Capability inventory: The skill utilizes subprocess calls via Ansible, privilege escalation (
become), and file-write operations. - Sanitization: No explicit sanitization or validation of the ingested playbook content is performed beyond the internal logic of the agent.
Audit Metadata