automation-audit-ops
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [NO_CODE]: This sk i l l is composed entirel y of inst ruct ional mar kdown with in SKIL L.md. It does not include an y scr i p t s, binar ies, or conf i g ur at ion fi les that execut e code.
- [PROMPT_INJECTION]: This sk i l l has a design-inherent sur face for indirect prompt inject ion because it direct s the agent to ingest and anal y ze untrust ed content from the work space.
- Ingest ion point s: The work f l ow in SKIL L.md spec i f ies read ing repo hook s, local hook scr i p t s, Git Hub Act ions, and wr apper scr i p t s.
- Boundar y mar ker s: The inst ruct ions lack del imiter s or spec i f i c war n ings to ignor e embedded inst ruct ions with in the fi les being audit ed.
- Capabil it y invent or y: The sk i l l ut i l i zes capabil it ies from ref erenc ed sk i l l s such as git hub-ops and work space-sur face-audit, whi ch may possess the abil it y to modi f y repositor y stat e or access the net work.
- Sanit i z at ion: No sanit i z at ion, val idat ion, or escap ing of the ingest ed fi le content is ment ioned in the work f l ow.
Audit Metadata