check-ci-health

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of CI configuration files, which presents a surface for indirect prompt injection.
  • Ingestion points: The agent is instructed to read various CI definition files, including .github/workflows/*.yml, Jenkinsfile, and .gitlab-ci.yml (SKILL.md).
  • Boundary markers: There are no explicit instructions or delimiters defined to separate the audited content from the agent's instructions, nor are there warnings to ignore embedded instructions within the data.
  • Capability inventory: The skill focus is on file reading and logical analysis; it does not request capabilities for network access, file writing, or command execution.
  • Sanitization: The skill lacks specific instructions for sanitizing or escaping the content of the ingested files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — check-ci-health