devops-team

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary focus is on promoting secure and reliable infrastructure engineering. It includes protocols for deployment safety, observability, and compliance auditing.
  • [SAFE]: External resource references point exclusively to authoritative and trusted technical documentation and standards bodies.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an inherent surface for indirect prompt injection as it is designed to analyze project-specific infrastructure files, Dockerfiles, and CI/CD configurations.
  • Ingestion points: Identified in context discovery phases within 'SKILL.md' and the pipeline design protocol.
  • Boundary markers: No specific boundary markers or instructions to isolate untrusted configuration data are provided in the agent prompts.
  • Capability inventory: The skill uses agents to generate deployment artifacts and perform dry-runs of infrastructure configurations.
  • Sanitization: There is no specific mention of sanitizing or validating external configuration strings before processing.
  • [OBFUSCATION]: A thorough scan for hidden commands, encoded payloads (Base64, hex), or suspicious character substitutions (zero-width characters, homoglyphs) yielded no results.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 05:05 PM
Security Audit — agent-trust-hub — devops-team