devops-automator

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external repository content (manifests, Dockerfiles, CI workflows) while maintaining access to high-privilege DevOps tools. This creates an inherent surface for indirect prompt injection.
  • Ingestion points: Reads and edits project files and configuration manifests via Read and Edit tools.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded instructions are present.
  • Capability inventory: Tool access includes Bash with docker, kubectl, terraform, helm, and gh as specified in the allowed-tools field.
  • Sanitization: The skill focuses on providing and validating configurations rather than sanitizing ingested content.
  • [EXTERNAL_DOWNLOADS]: The reference configurations utilize well-known GitHub Actions from trusted organizations for pipeline security and deployment. Examples include Aqua Security's Trivy scanner, Truffle Security's TruffleHog, and Azure's kubectl setup. These represent standard, secure DevOps practices.
  • [CREDENTIALS_UNSAFE]: The github-actions-patterns.yaml reference file contains hardcoded credentials for a local PostgreSQL test service (POSTGRES_PASSWORD: postgres). These are functional placeholders for a temporary integration testing container and do not pose a risk to actual credentials.
  • [SAFE]: The skill instructions and scripts actively encourage security best practices, including running containers as non-root users, setting resource limits, and implementing secret scanning. The provided validation script (validate-devops-skill.sh) correctly identifies security anti-patterns in user configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:30 AM
Security Audit — agent-trust-hub — devops-automator