ml-ops-engineer
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its processing of external datasets and configuration files.\n
- Ingestion points: The tools
drift_detector.py(reading CSV viacsv.DictReader) andpipeline_validator.py(reading JSON viajson.load) ingest untrusted data from the local environment.\n - Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard natural language commands that might be embedded within the CSV data or JSON values.\n
- Capability inventory: The skill possesses the capability to modify local state via
model_registry.py(_save_registry) and provides instructions for critical infrastructure operations such as Kubernetes deployment (k8s/model-deployment.yaml) and model serving.\n - Sanitization: The
drift_detector.pyscript implements basic type checks (_is_numeric), whilepipeline_validator.pyuses regex (CRON_PATTERN) to validate specific fields, but neither implements comprehensive sanitization against embedded natural language instructions.
Audit Metadata