netmiko-ssh-automation

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill patterns involve processing data from external network devices which can be considered untrusted input.
  • Ingestion points: Command output is retrieved via conn.send_command() and conn.send_config_set() in SKILL.md.
  • Boundary markers: Not explicitly present in the provided code snippets, though the skill advises separate verification.
  • Capability inventory: The skill uses tools for configuration changes (conn.send_config_set()) and privilege escalation (conn.enable()) on target devices.
  • Sanitization: The skill documentation recommends manual operator verification and mentions that configuration logs should be sanitized before sharing.
  • [SAFE]: The skill functions as a best-practices guide for secure network automation. It correctly demonstrates secure credential handling by using os.environ and getpass instead of hardcoding, and implements defensive measures such as connection timeouts, bounded concurrency, and operational dry-run flags.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — netmiko-ssh-automation