devops-engineer
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: CRITICALINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes application code and infrastructure configuration files to generate CI/CD pipelines and deployment manifests, creating a surface for indirect prompt injection if source files are malicious. Ingestion points include the agent's analysis of Dockerfiles, Kubernetes manifests, and Terraform configurations provided by the user. Capability inventory: The skill utilizes
kubectl,docker,terraform, and various cloud CLIs (aws,gcloud,az) to execute deployments and manage infrastructure. Boundary markers: No specific delimiters are defined to separate user-provided configuration data from the agent's instructions. Sanitization: There is no explicit mechanism described for validating or escaping external content before interpolation into commands or manifests. - [COMMAND_EXECUTION]: The skill relies on a wide range of shell commands and command-line utilities for automation and incident response. Evidence: Scripts across reference files utilize
kubectl,terraform,docker,gh,git,tcpdump, andslack-clifor operational tasks. - [EXTERNAL_DOWNLOADS]: The skill contains a reference to external documentation hosted on the author's GitHub Pages site. Evidence:
SKILL.mdincludes a link to documentation athttps://jeffallan.github.io/claude-skills/skills/devops/devops-engineer/which aligns with the author's specified identity.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata