digitalocean

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access detected. The skill provides legitimate instructions for DevOps tasks and infrastructure management.
  • [DATA_EXFILTRATION]: Instructions for handling DigitalOcean and Spaces credentials follow security best practices by using variables and environment variables (such as DIGITALOCEAN_TOKEN, AWS_ACCESS_KEY_ID, and AWS_SECRET_ACCESS_KEY) rather than hardcoding secrets.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from DigitalOcean account inventory (e.g., Droplet names, tags, firewall rules) via doctl and terraform. While the skill lacks explicit boundary markers between tool results, the capability to mutate infrastructure is the intended primary purpose of the skill and does not include autonomous execution of instructions found within that data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 04:54 PM
Security Audit — agent-trust-hub — digitalocean