check-ci-health
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of CI configuration files, which presents a surface for indirect prompt injection.
- Ingestion points: The agent is instructed to read various CI definition files, including .github/workflows/*.yml, Jenkinsfile, and .gitlab-ci.yml (SKILL.md).
- Boundary markers: There are no explicit instructions or delimiters defined to separate the audited content from the agent's instructions, nor are there warnings to ignore embedded instructions within the data.
- Capability inventory: The skill focus is on file reading and logical analysis; it does not request capabilities for network access, file writing, or command execution.
- Sanitization: The skill lacks specific instructions for sanitizing or escaping the content of the ingested files before processing.
Audit Metadata