skills/elzawarudo/krt/krt-ci-questor/Gen Agent Trust Hub

krt-ci-questor

Pass

Audited by Gen Agent Trust Hub on May 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes official platform CLIs such as gh (GitHub), glab (GitLab), and circleci to retrieve job logs, annotations, and metadata.
  • [EXTERNAL_DOWNLOADS]: References external documentation and research literature from well-known and trusted domains including docs.github.com, docs.gitlab.com, circleci.com, and arxiv.org.
  • [SAFE]: The skill incorporates explicit safety protocols in references/safety.md and SKILL.md to ensure secrets, tokens, and credentials are never printed or exposed during the investigation process.
  • [SAFE]: Instructions strictly forbid the agent from mutating remote CI state (e.g., rerunning jobs or changing configurations) without explicit user authorization.
  • [PROMPT_INJECTION]: The skill processes untrusted external data in the form of CI logs and repository files, creating a surface for indirect prompt injection; however, the structured playbook and focus on specific failure signatures mitigate the risk of the agent obeying embedded commands.
Audit Metadata
Risk Level
SAFE
Analyzed
May 29, 2026, 08:15 AM
Security Audit — agent-trust-hub — krt-ci-questor