devops-progressive-delivery

Warn

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [OBFUSCATION]: Multiple reference files, including 'architecture-patterns.md', 'code-organization.md', and 'testing-strategies.md', contain 150 repetitive sections of identical technical jargon. This 'wall of text' pattern is an obfuscation method that can be used to hide malicious instructions, conceal small payloads, or exhaust the agent's context window.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits a significant attack surface because it processes deployment environment data from the user and generates configurations for external tools with shell execution capabilities.
  • Ingestion points: Infrastructure context, service mesh details, and metric platform settings are provided by the user in 'SKILL.md'.
  • Boundary markers: None identified in the prompt templates.
  • Capability inventory: The skill defines YAML manifests for Flagger webhooks and Argo Rollouts analysis jobs (in 'SKILL.md' and 'flagger-config.md') that execute shell commands such as 'hey', 'curl', and 'kubectl' inside a cluster environment.
  • Sanitization: External content provided as input context is interpolated into deployment templates without explicit validation or escaping, which could allow for command injection into the generated manifests.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 13, 2026, 02:14 PM
Security Audit — agent-trust-hub — devops-progressive-delivery