devops-engineer
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFECREDENTIALS_UNSAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The file references/kubernetes.md contains a hardcoded connection string with dummy credentials (postgres://user:pass@host:5432/db) in a Kubernetes Secret manifest example. While these are placeholders, they trigger credential exposure patterns.
- [DATA_EXFILTRATION]: The collect-evidence.sh script in references/incident-response.md automates the collection of highly sensitive information, including network traffic captures via tcpdump, database process monitoring through pg_stat_activity, and full exports of Kubernetes resource configurations. This capability could be leveraged to harvest sensitive environment data.
- [COMMAND_EXECUTION]: The skill provides numerous scripts and examples that utilize high-privilege CLI tools, including kubectl, terraform, docker, and the GitHub CLI (gh), to manage infrastructure and deployment environments.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8). 1. Ingestion points: User-provided application requirements and environment descriptions in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: High-privilege access via kubectl, terraform, and shell scripts across all files. 4. Sanitization: Absent; user data is interpolated into code templates without validation.
Audit Metadata