sre-engineer

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection vulnerability surface detected. The skill's core function involves processing untrusted external data which could contain malicious instructions.
  • Ingestion points: Service architecture, reliability requirements, and existing SLOs are gathered from the project environment as described in SKILL.md.
  • Boundary markers: The instructions lack delimiters to separate ingested data from the agent's internal logic.
  • Capability inventory: The skill utilizes powerful tools including Python, Go, Terraform, and Kubernetes for automation as noted in SKILL.md.
  • Sanitization: There are no instructions to validate or sanitize the data retrieved from the project context.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 10:54 AM
Security Audit — agent-trust-hub — sre-engineer