microservices-analyst
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXFILTRATION]: The skill instructs the agent to identify and audit sensitive data within the microservice estate, including database connection strings, secrets sprawl, and environment variables in Kubernetes or Terraform manifests. This access is limited to analysis and reporting within the agent session and is a core part of the skill's intended auditing function.
- [PROMPT_INJECTION]: The skill is designed to process untrusted data from the analyzed environment, which creates a surface for indirect prompt injection attacks. 1. Ingestion points: Service catalogs, API gateways, application logs, tracing data, infrastructure manifests (K8s/Terraform), and API/Event schema repositories (OpenAPI/Protobuf). 2. Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the processed data. 3. Capability inventory: The skill performs data reading and analysis tasks; it does not explicitly use shell execution or network exfiltration tools, though it guides the agent in using available discovery tools. 4. Sanitization: There are no requirements for sanitizing or validating the content of external files or telemetry data before processing.
Audit Metadata