ci-cd-pipeline-builder
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to read and analyze project files (such as lockfiles, manifests, and source code) to generate CI/CD configurations. This pattern of processing untrusted data creates a potential surface for indirect prompt injection.\n
- Ingestion points: The scripts
scripts/pipeline_generator.py,scripts/cache_optimizer.py, andscripts/pipeline_linter.pyread content from files within the target directory.\n - Boundary markers: The analysis scripts do not appear to implement explicit delimiters or 'ignore instructions' directives when parsing project file content.\n
- Capability inventory: The agent can read project files, execute the included Python scripts, and write generated YAML pipeline definitions to the repository.\n
- Sanitization: The tool identifies stack components using regular expressions but does not perform comprehensive sanitization of file content before using it to generate output or logs.\n- [REMOTE_CODE_EXECUTION]: The CI/CD pipeline templates included in the skill reference multiple external GitHub Actions for automated tasks.\n
- Evidence: Templates in
references/pipeline-templates.mdutilize actions such aspnpm/action-setup@v4,astral-sh/setup-uv@v4,codecov/codecov-action@v4, andaquasecurity/trivy-action@master. These resources originate from well-known technology and security organizations.\n - Note: The reference to
aquasecurity/trivy-action@masteruses a mutable branch tag, which may introduce instability or security risks if the branch content changes unexpectedly.\n- [COMMAND_EXECUTION]: The skill uses Python scripts to perform local filesystem operations necessary for pipeline generation.\n - Evidence:
scripts/pipeline_generator.pyandscripts/cache_optimizer.pytraverse project directories and read file contents to identify the technology stack and suggest caching optimizations.
Audit Metadata