security-devops-assessment
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill serves as a diagnostic and assessment tool for DevSecOps practices, using structured markdown templates to guide the agent through various security evaluation phases.
- [NO_CODE]: The skill does not contain any executable scripts (Python, JavaScript, etc.) or binary files. It relies entirely on natural language instructions and structured metadata.
- [PROMPT_INJECTION]: No malicious patterns such as 'ignore previous instructions', system prompt extraction, or safety bypass attempts were detected in the instructions.
- [DATA_EXFILTRATION]: There are no network-capable commands (e.g., curl, wget) or attempts to access sensitive local files (e.g., SSH keys, environment variables). The required connections to CI/CD and security tools are consistent with the skill's stated purpose.
- [COMMAND_EXECUTION]: No shell command execution or subprocess spawning patterns were found.
Audit Metadata