infrastructure-doc-sync
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes runtime infrastructure data and repository files to update workspace documentation.
- Ingestion points: Host metadata, container configurations (e.g., docker-compose files), repository state, and service APIs.
- Boundary markers: Absent from prompt instructions.
- Capability inventory: File-write access to repository documents (README.md, AGENTS.md), operational runbooks, and dashboard configuration files.
- Sanitization: Includes robust safety guidelines explicitly prohibiting the agent from publishing credentials, tokens, private addresses, or sensitive internal details.
- [DATA_EXPOSURE_AND_EXFILTRATION]: While the skill accesses sensitive runtime infrastructure data to generate documentation, it implements strict constraints to prevent the leakage of secrets, private file paths, or internal operational details into the documentation surfaces.
Audit Metadata