devops-automator
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external repository content (manifests, Dockerfiles, CI workflows) while maintaining access to high-privilege DevOps tools. This creates an inherent surface for indirect prompt injection.
- Ingestion points: Reads and edits project files and configuration manifests via
ReadandEdittools. - Boundary markers: No explicit boundary markers or instructions to ignore embedded instructions are present.
- Capability inventory: Tool access includes
Bashwithdocker,kubectl,terraform,helm, andghas specified in theallowed-toolsfield. - Sanitization: The skill focuses on providing and validating configurations rather than sanitizing ingested content.
- [EXTERNAL_DOWNLOADS]: The reference configurations utilize well-known GitHub Actions from trusted organizations for pipeline security and deployment. Examples include Aqua Security's Trivy scanner, Truffle Security's TruffleHog, and Azure's kubectl setup. These represent standard, secure DevOps practices.
- [CREDENTIALS_UNSAFE]: The
github-actions-patterns.yamlreference file contains hardcoded credentials for a local PostgreSQL test service (POSTGRES_PASSWORD: postgres). These are functional placeholders for a temporary integration testing container and do not pose a risk to actual credentials. - [SAFE]: The skill instructions and scripts actively encourage security best practices, including running containers as non-root users, setting resource limits, and implementing secret scanning. The provided validation script (
validate-devops-skill.sh) correctly identifies security anti-patterns in user configurations.
Audit Metadata