skills/eugene-ee/affaan-m-ecc/uncloud/Gen Agent Trust Hub

uncloud

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill acts as a legitimate documentation resource for the Uncloud cluster management platform. The instructions and examples provided follow standard infrastructure-as-code best practices and do not exhibit malicious intent.\n- [COMMAND_EXECUTION]: The skill describes the use of the uc CLI for managing cluster resources, including deploying services (uc deploy) and managing machines (uc machine init). These commands are essential to the tool's function and are described in a safe, reference-oriented context.\n- [EXTERNAL_DOWNLOADS]: The documentation references the registry.k8s.io container registry for a utility image (pause). This is a well-known and trusted infrastructure service, and its use is documented neutrally.\n- [INDIRECT_PROMPT_INJECTION]: The skill details workflows that ingest external configuration data from compose.yaml files and Caddyfile snippets, which is a common surface for indirect prompt injection in DevOps tooling.\n
  • Ingestion points: compose.yaml via uc deploy and external Caddyfiles via the --caddyfile flag.\n
  • Boundary markers: The skill does not provide specific delimiters or warnings to ignore instructions found within these configuration files.\n
  • Capability inventory: uc deploy, uc service run, uc service exec, and uc machine init provide the ability to modify system state and execute code within containers.\n
  • Sanitization: The reference guidelines do not include explicit methods for validating or sanitizing the content of external configuration files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — uncloud