devops

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as CI/CD configurations, Dockerfiles, and Infrastructure-as-Code (IaC) files using tools like view_file and grep_search. * Ingestion points: Project repository files including pipeline definitions, deployment scripts, and Helm charts. * Boundary markers: The skill contains explicit instructions in references/security.md to avoid prompt concatenation with untrusted input and identifies LLM-specific vulnerabilities like prompt injection (LLM01). * Capability inventory: The agent has access to powerful tools including bash, run_command, write_to_file, and replace_file_content across all scripts. * Sanitization: The skill documents anti-patterns such as raw-output sinks and promotes the use of security scanners (Trivy, Checkov, Semgrep) to validate infrastructure before deployment.
  • [EXTERNAL_DOWNLOADS]: The skill's procedures are enriched by methodologies and templates sourced from several third-party GitHub repositories. * Evidence: The references/cicd.md and references/security.md files reference repositories such as wshobson/agents, humanlayer/skills, addyosmani/agent-skills, BagelHole/sast-scanning, and HoangNguyen/common-llm-security for CI/CD templates, monitoring dashboards, and security scanning configurations. * Trusted Sources: The skill correctly references official resources such as the microsoft/azure-skills repository and the Google Cloud Well-Architected Framework for infrastructure guidance.
  • [COMMAND_EXECUTION]: The skill is designed to facilitate the execution of shell commands and infrastructure deployment tools. * Evidence: It utilizes bash and run_command tools to perform tasks such as Helm chart installations, Terraform operations, and security audit sweeps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — devops