skills/iwanhe/pandawa/senior-devops/Gen Agent Trust Hub

senior-devops

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill scripts ingest user-provided paths, which serves as a potential vector for indirect prompt injection if the agent interacts with untrusted data in those directories.\n
  • Ingestion points: The target argument in scripts/pipeline_generator.py, scripts/terraform_scaffolder.py, and scripts/deployment_manager.py defines the scope of file ingestion.\n
  • Boundary markers: The skill does not implement delimiters or safety instructions to distinguish between agent commands and data found in user files.\n
  • Capability inventory: Documentation in SKILL.md describes the use of powerful system tools including terraform, docker, kubectl, and aws-cli to perform infrastructure changes.\n
  • Sanitization: The Python scripts lack validation or sanitization of the content within the targeted directories, relying on the existence of the path.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:33 PM
Security Audit — agent-trust-hub — senior-devops