launch-trigger-and-monitor-launch-deployments

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and analyzes deployment logs from the Launch API to provide failure summaries and recommendations. This ingestion of potentially untrusted data represents an attack surface for indirect prompt injection.
  • Ingestion points: Deployment logs are fetched via the GET /projects/{project_uid}/environments/{environment_uid}/deployments/{deployment_uid} endpoint as described in the instructions.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the fetched log content.
  • Capability inventory: The skill uses the Bash tool to perform network API calls and the Read/Write tools for local environment interaction.
  • Sanitization: The instructions focus on summarizing the cause and recommending next steps but do not include specific sanitization or filtering requirements for the log data before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:43 PM