devops-workflow-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's analysis tool ingests untrusted external data, creating a surface for indirect prompt injection.
- Ingestion points: The script
scripts/pipeline_analyzer.pyreads existing GitHub Actions workflow files from the user's project to identify optimization opportunities. - Boundary markers: The tool does not implement explicit boundary markers or instructions to the agent to disregard potential natural language directives embedded within the YAML files (e.g., in comments or metadata fields).
- Capability inventory: The skill possesses the capability to generate new workflow YAML and deployment strategies. A malicious input file could attempt to trick the agent into recommending or generating backdoored CI/CD configurations.
- Sanitization: The input files are parsed for structure but the content is not sanitized to remove or neutralize potential prompt injection attempts before the analysis results are returned to the agent.
Audit Metadata