virtualization

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill features an indirect prompt injection surface. Ingestion points: Data from virtualization environments, such as VM names, tags, and resource labels, are queried using diagnostic scripts like cloud-vms/scripts/01-aws-ec2-health.sh and vmware/scripts/02-powercli-inventory.ps1. Boundary markers: The skill does not employ explicit delimiters to separate this external data from the agent's instructional context. Capability inventory: The skill provides instructions and commands for VM lifecycle management, including deletion and modification across multiple platforms. Sanitization: The ingested metadata is processed and displayed without sanitization or filtering. While this is an expected surface for administrative tools, it allows potentially malicious environment data to enter the agent's context.
  • [DATA_EXFILTRATION]: Diagnostic scripts such as 01-xe-health.sh and 03-gce-health.sh collect system configuration data, including account identifiers and network details. This activity is aligned with the skill's primary purpose of infrastructure monitoring and inventory. The information gathered remains within the user's session, with no evidence of exfiltration to external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 01:31 PM
Security Audit — agent-trust-hub — virtualization