devops-troubleshooter

Pass

Audited by Gen Agent Trust Hub on May 3, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of Markdown instructions and reference documentation. It does not include executable scripts (e.g., Python or JavaScript files) or compiled binaries.
  • [COMMAND_EXECUTION]: While the reference files (incident-runbook-templates.md and on-call-handoff-patterns.md) contain many shell command examples such as kubectl, curl, and psql, these are provided as static templates for human or agent-assisted troubleshooting. There are no instructions for the agent to execute these commands automatically or dangerously.
  • [PROMPT_INJECTION]: The skill follows standard instructional patterns for its role. No attempts to bypass safety filters, extract system prompts, or override agent constraints were detected.
  • [DATA_EXFILTRATION]: No network operations to non-whitelisted or suspicious domains were found. The examples provided use internal-facing tools (Prometheus, Kubernetes API) for diagnostic purposes.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze logs and monitoring data, which is an inherent risk surface for indirect injection. However, the instructions emphasize systematic hypothesis testing and documentation, and do not contain unsafe interpolation of external data into executable contexts.
Audit Metadata
Risk Level
SAFE
Analyzed
May 3, 2026, 06:21 PM
Security Audit — agent-trust-hub — devops-troubleshooter