devops-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides comprehensive and secure templates for Docker, Kubernetes, and CI/CD pipelines. It explicitly enforces best practices like non-root users, image scanning, and secure secret management.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves generating executable code and configurations based on external requirements, which is a potential surface for injection attacks. 1. Ingestion points: User-provided application specifications and environment details (SKILL.md). 2. Boundary markers: None present in the instructions. 3. Capability inventory: Shell command execution via kubectl, docker, terraform, and GitHub CLI; Python script execution for remediation. 4. Sanitization: The skill does not provide instructions for sanitizing or validating user-provided strings before interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:19 PM
Security Audit — agent-trust-hub — devops-engineer