ci-cd-and-automation
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes a feedback loop where users are encouraged to paste CI failure output directly into the agent's context to facilitate automated fixes.
- Ingestion points: User-provided CI failure logs pasted into the prompt as described in the 'Feeding CI Failures Back to Agents' section of
SKILL.md. - Boundary markers: The instructions suggest wrapping the error in a natural language prompt (e.g., 'The CI pipeline failed with this error: [paste specific error]') but do not include formal delimiters or warnings for the agent to ignore embedded instructions within the logs.
- Capability inventory: The agent is expected to execute local commands such as
npm run lint --fix, modify source files, and commit changes. - Sanitization: No sanitization or validation of the pasted log content is mentioned, which could allow an attacker to influence the agent's behavior if they can control the output of a failing CI step (e.g., via a malicious pull request).
Audit Metadata