sre-engineer
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection vulnerability surface detected. The skill's core function involves processing untrusted external data which could contain malicious instructions.
- Ingestion points: Service architecture, reliability requirements, and existing SLOs are gathered from the project environment as described in SKILL.md.
- Boundary markers: The instructions lack delimiters to separate ingested data from the agent's internal logic.
- Capability inventory: The skill utilizes powerful tools including Python, Go, Terraform, and Kubernetes for automation as noted in SKILL.md.
- Sanitization: There are no instructions to validate or sanitize the data retrieved from the project context.
Audit Metadata