sre
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill ingests untrusted data from the repository's infrastructure configurations which could be used to influence agent behavior.
- Ingestion points: infrastructure/kubernetes/, infrastructure/terraform/, and .github/workflows/ as defined in phases/01-readiness-review.md.
- Boundary markers: Not present in the prompt templates.
- Capability inventory: The skill writes multiple files to the workspace (docs/runbooks/, .forgewright/sre/) and generates shell commands for execution.
- Sanitization: No evidence of input sanitization or verification of the ingested infrastructure code.
- [COMMAND_EXECUTION]: Dynamic Context Injection. The SKILL.md file uses the exclamation-backtick syntax to execute shell commands at load time. These commands are used to read local protocol and configuration files like ux-protocol.md and codebase-context.md.
- [COMMAND_EXECUTION]: Shell Command Generation. The skill generates operational runbooks in phases/04-incident-management.md that contain specific shell commands (e.g., kubectl exec, kubectl rollout undo) for the agent or user to run against production infrastructure.
Audit Metadata