devops
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes dynamic context injection using the
!catsyntax to execute shell commands when the skill is loaded. These commands are hardcoded to read project-specific configuration and protocol files (e.g., .production-grade.yaml, .forgewright/settings.md) and inject their contents into the agent prompt. These commands do not process user-provided arguments. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection. Ingestion points:
!catcommands in SKILL.md and project infrastructure reads. Boundary markers: Absent. Capability inventory: Extensive file-writing and script generation capabilities (e.g., writing to .github/workflows/ and infrastructure/ directories). Sanitization: Absent. The lack of delimiters for injected content allows malicious instructions in local configuration files to potentially influence the agent's deployment and configuration tasks.
Audit Metadata