devops-engineer
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides comprehensive templates for DevOps tasks including CI/CD pipelines, Kubernetes orchestration, and Infrastructure as Code. It incorporates security best practices such as utilizing secret managers instead of environment files, implementing container security scanning, and enforcing non-root users in Docker images.
- [COMMAND_EXECUTION]: The skill makes extensive use of CLI tools including kubectl, docker, terraform, and gh. These commands are standard for DevOps automation and are documented within the context of deployment, infrastructure management, and incident response workflows.
- [EXTERNAL_DOWNLOADS]: CI/CD pipeline examples reference official GitHub Actions and tools from established security vendors like Aqua Security and Sigstore. These references are within the expected scope for infrastructure automation.
- [INDIRECT_PROMPT_INJECTION]: The skill processes infrastructure configurations which presents an ingestion surface for untrusted data. 1. Ingestion points: Dockerfiles, Kubernetes manifests, and Terraform scripts (references/kubernetes.md, references/terraform-iac.md). 2. Boundary markers: Constraints in SKILL.md explicitly prohibit production deployment without approval. 3. Capability inventory: Subprocess calls to kubectl, docker, and terraform, plus network operations via curl and gh. 4. Sanitization: The workflow requires terraform plan, linting, and manual verification before execution.
Audit Metadata