devops

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes dynamic context injection using the !cat syntax to execute shell commands when the skill is loaded. These commands are hardcoded to read project-specific configuration and protocol files (e.g., .production-grade.yaml, .forgewright/settings.md) and inject their contents into the agent prompt. These commands do not process user-provided arguments.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection. Ingestion points: !cat commands in SKILL.md and project infrastructure reads. Boundary markers: Absent. Capability inventory: Extensive file-writing and script generation capabilities (e.g., writing to .github/workflows/ and infrastructure/ directories). Sanitization: Absent. The lack of delimiters for injected content allows malicious instructions in local configuration files to potentially influence the agent's deployment and configuration tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 07:29 PM
Security Audit — agent-trust-hub — devops