pipeline-security
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains a 'Prompt Injection Safety Notice' that mentions phrases like 'ignore previous instructions'. Evaluation of the context reveals this is a defensive measure intended to protect the agent from malicious content within analyzed CI/CD configurations, rather than an attempt to override system behavior.
- [DATA_EXFILTRATION]: While the skill is designed to identify insecure credential hygiene, it includes explicit instructions to never exfiltrate secrets found during analysis. It mandates that any sensitive values discovered must be redacted or referenced generically in the final report.
- [INDIRECT_PROMPT_INJECTION]: The skill evaluates untrusted external data (pipeline configuration files). To mitigate this risk, it provides clear boundary instructions, directing the agent to treat all file contents as data to be analyzed and strictly forbidding the execution of any code or instructions found within those files.
Audit Metadata