gitops-repo-audit
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as a security auditing extension. It is designed to find misconfigurations, deprecated APIs, and secrets exposure in GitOps repositories. All behaviors are consistent with its stated purpose.
- [EXTERNAL_DOWNLOADS]: Documentation and reference links point to official vendor sites (
fluxcd.io,fluxoperator.dev) and trusted GitHub repositories (github.com/fluxcd). These are verified and trusted sources. - [COMMAND_EXECUTION]: The skill executes local bash scripts (
discover.sh,validate.sh,check-deprecated.sh) which wrap official Flux and Kubernetes CLI utilities. It correctly usesmktempfor temporary files and implements appropriate cleanup traps. - [DATA_EXFILTRATION]: No data exfiltration patterns were detected. The skill specifically instructs the agent to audit for plain-text secrets and report them as a risk, but it does not transmit this data to untrusted external endpoints.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface as it processes untrusted Git repository manifests. However, it uses structured parsing via official CLI tools and does not exhibit vulnerabilities that would allow external data to override the agent's instructions.
- Ingestion points: Scans files in the user-provided repository path via
scripts/discover.sh. - Boundary markers: The skill instructions assume tool-based parsing of manifests, reducing the risk of direct obedience to embedded strings.
- Capability inventory: Limited to local CLI execution and file reads.
- Sanitization: Relies on standard parsers within
flux-schemaandkustomize.
Audit Metadata