managing-digitalocean-spaces
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
awsanddoctlcommand-line tools to interact with DigitalOcean cloud services. These commands are integral to the skill's stated purpose of managing object storage and CDN resources. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes data from external cloud resources without explicit sanitization. * Ingestion points: The skill reads object keys via
aws s3api list-objects-v2and CDN configuration viadoctl compute cdn list. * Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious content embedded in resource names or metadata. * Capability inventory: The agent has access to powerful CLI tools (aws,doctl) and data processing utilities (jq). * Sanitization: No validation or filtering is applied to the metadata retrieved from the DigitalOcean environment before it is presented in the agent's context.
Audit Metadata