devops-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides utility scripts that are susceptible to command injection if their arguments are sourced from untrusted external data without validation.
  • Ingestion points: Scripts such as collect-evidence.sh in references/incident-response.md and release.sh in references/release-automation.md accept command-line arguments (e.g., INCIDENT_ID, VERSION) that may be derived from external events.
  • Boundary markers: There are no instructions or boundary markers defined to ensure the agent validates or sanitizes these inputs before use.
  • Capability inventory: The skill provides access to powerful tools including kubectl exec, gh (GitHub CLI), and git, which increase the potential impact of an injection attack.
  • Sanitization: Inputs are interpolated directly into shell strings (e.g., mkdir -p incidents/${INCIDENT_ID}/evidence) without escaping or validation.
  • [COMMAND_EXECUTION]: The skill includes several scripts designed to automate infrastructure and incident response tasks.
  • Evidence: references/incident-response.md contains scripts that execute kubectl exec, tcpdump, and psql to collect forensics. references/release-automation.md includes a coordination script that uses gh and git for release management.
  • [EXTERNAL_DOWNLOADS]: The skill references and utilizes various well-known third-party tools and GitHub Actions for security scanning and deployment.
  • Evidence: The skill utilizes aquasecurity/trivy-action for container scanning, sigstore/cosign-installer for artifact signing, and official actions from the actions/ and docker/ GitHub organizations. These are recognized as well-known and reputable services.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — devops-engineer