buildkite-migration

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the 'bk' CLI via Homebrew or from Buildkite's official GitHub releases. These sources are official distribution channels for the vendor's software.
  • [COMMAND_EXECUTION]: The skill executes the 'bk pipeline convert' command to process CI/CD configuration files. This is the core functionality intended for the migration task.
  • [DATA_EXFILTRATION]: Configuration files are sent to a public API for conversion. This behavior is explicitly described in the skill documentation and is a standard part of the vendor's conversion service.
  • [PROMPT_INJECTION]: The skill includes specific instructions to the agent to output converted results as a YAML code block without further commentary, which acts as a protective boundary against potential instructions embedded in the source data.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 01:56 AM