skills/buiphucminhtam/forgewright/sre/Gen Agent Trust Hub

sre

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill ingests untrusted data from the repository's infrastructure configurations which could be used to influence agent behavior.
  • Ingestion points: infrastructure/kubernetes/, infrastructure/terraform/, and .github/workflows/ as defined in phases/01-readiness-review.md.
  • Boundary markers: Not present in the prompt templates.
  • Capability inventory: The skill writes multiple files to the workspace (docs/runbooks/, .forgewright/sre/) and generates shell commands for execution.
  • Sanitization: No evidence of input sanitization or verification of the ingested infrastructure code.
  • [COMMAND_EXECUTION]: Dynamic Context Injection. The SKILL.md file uses the exclamation-backtick syntax to execute shell commands at load time. These commands are used to read local protocol and configuration files like ux-protocol.md and codebase-context.md.
  • [COMMAND_EXECUTION]: Shell Command Generation. The skill generates operational runbooks in phases/04-incident-management.md that contain specific shell commands (e.g., kubectl exec, kubectl rollout undo) for the agent or user to run against production infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — sre