buildkite-migration
Pass
Audited by Gen Agent Trust Hub on Apr 30, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the 'bk' CLI via Homebrew or from Buildkite's official GitHub releases. These sources are official distribution channels for the vendor's software.
- [COMMAND_EXECUTION]: The skill executes the 'bk pipeline convert' command to process CI/CD configuration files. This is the core functionality intended for the migration task.
- [DATA_EXFILTRATION]: Configuration files are sent to a public API for conversion. This behavior is explicitly described in the skill documentation and is a standard part of the vendor's conversion service.
- [PROMPT_INJECTION]: The skill includes specific instructions to the agent to output converted results as a YAML code block without further commentary, which acts as a protective boundary against potential instructions embedded in the source data.
Audit Metadata