argocd-operations
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface because it directs the agent to analyze data from potentially untrusted external sources.
- Ingestion points: The agent is instructed to read output from the
argocd app get --show-operationcommand and analyze Kubernetes resource events (SKILL.md, Section 5). - Boundary markers: No explicit delimiters or instructions are provided to the agent to treat external tool output as untrusted data.
- Capability inventory: The skill references the execution of
argocdandkubectlCLI tools (references/argocd-troubleshooting.md). - Sanitization: No sanitization or validation logic is defined for the ingested data.
Audit Metadata