infra-secrets-config

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for the agent to analyze external, untrusted infrastructure artifacts which may contain malicious instructions designed to manipulate the agent's output or audit results.
  • Ingestion points: The 'Evidence' section in SKILL.md identifies job specs, Dockerfiles, proxy configurations, deployment manifests, and system logs as primary data sources for ingestion.
  • Boundary markers: There are no explicit instructions for the agent to use delimiters or to treat data within these infrastructure files as untrusted content that should not be followed as instructions.
  • Capability inventory: The skill allows the agent to review configurations, report risks, and collect evidence from system states and logs. It does not provide automated script execution or network tools that could be abused by an injection.
  • Sanitization: No sanitization or filtering protocols are defined for handling the external configuration data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:31 PM
Security Audit — agent-trust-hub — infra-secrets-config