ml-ops-engineer

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its processing of external datasets and configuration files.\n
  • Ingestion points: The tools drift_detector.py (reading CSV via csv.DictReader) and pipeline_validator.py (reading JSON via json.load) ingest untrusted data from the local environment.\n
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard natural language commands that might be embedded within the CSV data or JSON values.\n
  • Capability inventory: The skill possesses the capability to modify local state via model_registry.py (_save_registry) and provides instructions for critical infrastructure operations such as Kubernetes deployment (k8s/model-deployment.yaml) and model serving.\n
  • Sanitization: The drift_detector.py script implements basic type checks (_is_numeric), while pipeline_validator.py uses regex (CRON_PATTERN) to validate specific fields, but neither implements comprehensive sanitization against embedded natural language instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 05:15 PM
Security Audit — agent-trust-hub — ml-ops-engineer