devops
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted user data, including product requirements, engineering specifications, and architecture diagrams, to produce operational artifacts like Infrastructure as Code (IaC) snippets and operational runbooks.\n
- Ingestion points: Untrusted data enters the agent context through user prompts during the discovery phase and the translation of requirements into infrastructure (SKILL.md and references/phase-1-discovery.md).\n
- Boundary markers: The instructions do not define explicit delimiters or use 'ignore-embedded-instructions' warnings when processing user-provided technical specifications.\n
- Capability inventory: The skill is used to generate configuration for powerful tools including Terraform, Kubernetes, and Cloud provider CLI commands, which could lead to the deployment of insecure infrastructure if the input specifications contain malicious overrides.\n
- Sanitization: There are no steps provided for the agent to sanitize or validate the technical specifications for embedded prompt injection patterns before generating IaC or documentation.
Audit Metadata