gitlab-ci-patterns

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The Kubernetes deployment template in SKILL.md includes the --insecure-skip-tls-verify=true flag. This disables SSL/TLS certificate validation for the kubectl command, which is a security risk that leaves the connection vulnerable to man-in-the-middle attacks.
  • [DYNAMIC_EXECUTION]: The 'Dynamic Child Pipelines' section in SKILL.md documents a pattern where a script (python generate_pipeline.py) generates a CI configuration file at runtime, which is then immediately executed via the trigger:include artifact directive.
  • [INDIRECT_PROMPT_INJECTION]: The dynamic pipeline pattern represents a surface for indirect instruction injection, as the agent context is influenced by dynamically generated content.
  • Ingestion points: The child-pipeline.yml artifact produced by the generate-pipeline job in SKILL.md.
  • Boundary markers: None; the template does not include delimiters or specific instructions to the pipeline runner to ignore untrusted content within the generated artifact.
  • Capability inventory: The pipeline uses the trigger capability to execute the instructions defined within the generated YAML file.
  • Sanitization: The skill does not demonstrate any validation, schema checking, or sanitization of the script's output before it is used to trigger a child pipeline.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — gitlab-ci-patterns