devops
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as CI/CD configurations, Dockerfiles, and Infrastructure-as-Code (IaC) files using tools like
view_fileandgrep_search. * Ingestion points: Project repository files including pipeline definitions, deployment scripts, and Helm charts. * Boundary markers: The skill contains explicit instructions inreferences/security.mdto avoid prompt concatenation with untrusted input and identifies LLM-specific vulnerabilities like prompt injection (LLM01). * Capability inventory: The agent has access to powerful tools includingbash,run_command,write_to_file, andreplace_file_contentacross all scripts. * Sanitization: The skill documents anti-patterns such as raw-output sinks and promotes the use of security scanners (Trivy, Checkov, Semgrep) to validate infrastructure before deployment. - [EXTERNAL_DOWNLOADS]: The skill's procedures are enriched by methodologies and templates sourced from several third-party GitHub repositories. * Evidence: The
references/cicd.mdandreferences/security.mdfiles reference repositories such aswshobson/agents,humanlayer/skills,addyosmani/agent-skills,BagelHole/sast-scanning, andHoangNguyen/common-llm-securityfor CI/CD templates, monitoring dashboards, and security scanning configurations. * Trusted Sources: The skill correctly references official resources such as themicrosoft/azure-skillsrepository and the Google Cloud Well-Architected Framework for infrastructure guidance. - [COMMAND_EXECUTION]: The skill is designed to facilitate the execution of shell commands and infrastructure deployment tools. * Evidence: It utilizes
bashandrun_commandtools to perform tasks such as Helm chart installations, Terraform operations, and security audit sweeps.
Audit Metadata