migrate-to-teamcity

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted CI/CD configuration files from the local repository (.github/workflows/ and bamboo-specs/), which constitutes a surface for indirect prompt injection.\n
  • Ingestion points: Local CI configuration directories (SKILL.md).\n
  • Boundary markers: The workflow incorporates manual review steps for generated content (SKILL.md).\n
  • Capability inventory: Uses the teamcity CLI for project configuration and handles shell script generation (SKILL.md, references/gotchas.md).\n
  • Sanitization: Relies on built-in validation tools and manual user oversight.\n- [COMMAND_EXECUTION]: Documentation provides examples of system commands such as 'sudo rm -rf' for managing tool versions on build agents (references/gotchas.md).\n- [EXTERNAL_DOWNLOADS]: Recommends the integration of well-known third-party scripts and CLIs, such as those from Codecov and GoReleaser, into the migrated pipelines (references/mappings.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 07:15 PM
Security Audit — agent-trust-hub — migrate-to-teamcity