devops-engineer
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides utility scripts that are susceptible to command injection if their arguments are sourced from untrusted external data without validation.
- Ingestion points: Scripts such as
collect-evidence.shinreferences/incident-response.mdandrelease.shinreferences/release-automation.mdaccept command-line arguments (e.g.,INCIDENT_ID,VERSION) that may be derived from external events. - Boundary markers: There are no instructions or boundary markers defined to ensure the agent validates or sanitizes these inputs before use.
- Capability inventory: The skill provides access to powerful tools including
kubectl exec,gh(GitHub CLI), andgit, which increase the potential impact of an injection attack. - Sanitization: Inputs are interpolated directly into shell strings (e.g.,
mkdir -p incidents/${INCIDENT_ID}/evidence) without escaping or validation. - [COMMAND_EXECUTION]: The skill includes several scripts designed to automate infrastructure and incident response tasks.
- Evidence:
references/incident-response.mdcontains scripts that executekubectl exec,tcpdump, andpsqlto collect forensics.references/release-automation.mdincludes a coordination script that usesghandgitfor release management. - [EXTERNAL_DOWNLOADS]: The skill references and utilizes various well-known third-party tools and GitHub Actions for security scanning and deployment.
- Evidence: The skill utilizes
aquasecurity/trivy-actionfor container scanning,sigstore/cosign-installerfor artifact signing, and official actions from theactions/anddocker/GitHub organizations. These are recognized as well-known and reputable services.
Audit Metadata