automation-audit-ops

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [NO_CODE]: This sk i l l is composed entirel y of inst ruct ional mar kdown with in SKIL L.md. It does not include an y scr i p t s, binar ies, or conf i g ur at ion fi les that execut e code.
  • [PROMPT_INJECTION]: This sk i l l has a design-inherent sur face for indirect prompt inject ion because it direct s the agent to ingest and anal y ze untrust ed content from the work space.
  • Ingest ion point s: The work f l ow in SKIL L.md spec i f ies read ing repo hook s, local hook scr i p t s, Git Hub Act ions, and wr apper scr i p t s.
  • Boundar y mar ker s: The inst ruct ions lack del imiter s or spec i f i c war n ings to ignor e embedded inst ruct ions with in the fi les being audit ed.
  • Capabil it y invent or y: The sk i l l ut i l i zes capabil it ies from ref erenc ed sk i l l s such as git hub-ops and work space-sur face-audit, whi ch may possess the abil it y to modi f y repositor y stat e or access the net work.
  • Sanit i z at ion: No sanit i z at ion, val idat ion, or escap ing of the ingest ed fi le content is ment ioned in the work f l ow.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 04:01 AM
Security Audit — agent-trust-hub — automation-audit-ops