site-reliability-engineering
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection vulnerability surface. (1) Ingestion points: The agent protocol in SKILL.md requires the agent to fetch and process untrusted context including system logs, metrics, and trace IDs. (2) Boundary markers: The instructions lack any defined delimiters or 'ignore embedded instructions' warnings for this external data. (3) Capability inventory: The skill identifies high-impact agent capabilities in SKILL.md, such as 'Rollback Deployment', 'Restart connection pool', and scaling infrastructure. (4) Sanitization: There are no explicit requirements or logic provided to filter or validate external system content before it enters the agent's context.
- [SAFE]: No hardcoded credentials, secrets, or sensitive file paths were detected in the skill's instructions or reference materials.
- [SAFE]: The skill consists entirely of Markdown files and does not include any executable scripts, binaries, or unverifiable external dependencies.
- [SAFE]: The skill's behavior and protocols are consistent with its stated purpose of managing site reliability engineering tasks.
Audit Metadata