devops-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines protocols for interacting with untrusted web content and external data, creating a potential surface area for indirect prompt injection.
  • Ingestion points: Web content and external data via BrowserOS (SKILL.md).
  • Boundary markers: Absent from the instructions, though the skill mandates treating such inputs as hostile.
  • Capability inventory: Terminal execution via ExecutionProxy (rtk), file system writes via MemoryStore, and issue tracker interaction.
  • Sanitization: Explicitly mandates redacting secrets and PII before sharing context.
  • [NO_CODE]: This skill consists exclusively of markdown documentation and instructions; it does not include any executable scripts, binaries, or configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 07:35 AM
Security Audit — agent-trust-hub — devops-engineer