devops-engineer

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: CRITICALINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes application code and infrastructure configuration files to generate CI/CD pipelines and deployment manifests, creating a surface for indirect prompt injection if source files are malicious. Ingestion points include the agent's analysis of Dockerfiles, Kubernetes manifests, and Terraform configurations provided by the user. Capability inventory: The skill utilizes kubectl, docker, terraform, and various cloud CLIs (aws, gcloud, az) to execute deployments and manage infrastructure. Boundary markers: No specific delimiters are defined to separate user-provided configuration data from the agent's instructions. Sanitization: There is no explicit mechanism described for validating or escaping external content before interpolation into commands or manifests.
  • [COMMAND_EXECUTION]: The skill relies on a wide range of shell commands and command-line utilities for automation and incident response. Evidence: Scripts across reference files utilize kubectl, terraform, docker, gh, git, tcpdump, and slack-cli for operational tasks.
  • [EXTERNAL_DOWNLOADS]: The skill contains a reference to external documentation hosted on the author's GitHub Pages site. Evidence: SKILL.md includes a link to documentation at https://jeffallan.github.io/claude-skills/skills/devops/devops-engineer/ which aligns with the author's specified identity.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — devops-engineer