managing-argocd

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs the argocd CLI and curl to interact with Kubernetes GitOps configurations. These operations are restricted to the intended scope of managing ArgoCD applications and clusters and do not pose a risk of unauthorized command execution.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted data from the ArgoCD API (e.g., sync messages and event logs). However, the risk is minimal as the data is used for reporting through structured tools like jq and is not used to dynamically construct executable code.
  • Ingestion points: Application names, resource status messages, and event logs retrieved via https://${ARGOCD_SERVER}/api/v1/applications and related endpoints in SKILL.md.
  • Boundary markers: None implemented for the data processed in shell loops.
  • Capability inventory: Uses argocd CLI for diffs and history, and curl for API synchronization and rollback commands in SKILL.md.
  • Sanitization: None; data is extracted using jq but not explicitly sanitized for natural language instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:21 PM
Security Audit — agent-trust-hub — managing-argocd