concourse-ci

Pass

Audited by Gen Agent Trust Hub on Oct 7, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXPOSURE]: The skill provides instructions and a shell code snippet to access and parse the ~/.flyrc file. This file contains sensitive bearer tokens for Concourse CI targets. The access is intended to facilitate cross-team pipeline management by programmatically extracting and cloning authorization tokens to avoid repeated interactive logins.
  • Evidence: references/best-practices.md contains a shell snippet: TOKEN=$(awk -v t=" <existing-target>:" '$0==t{i=1;next} i&&/^ [a-z]/{i=0} i&&/value:/{sub(/^[[:space:]]*value:[[:space:]]*/,"");print;exit}' ~/.flyrc).
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a validation script (scripts/validate-pipeline.sh) and instructions for tools like fly execute that process user-supplied YAML configuration files. This represents an attack surface where malicious instructions embedded in a pipeline file could influence the agent's behavior during the validation or local execution process.
  • Ingestion points: scripts/validate-pipeline.sh (file path arguments), fly execute -c (task configuration files).
  • Boundary markers: Not present.
  • Capability inventory: Bash(fly), Bash(yq), Read, Write, Glob, Grep.
  • Sanitization: scripts/validate-pipeline.sh uses yq with the strenv() function to handle variables, which mitigates potential shell injection risks within the validator's logic.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the fly CLI and yq utility for Concourse pipeline management, validation, and local task execution. The instructions guide the agent to perform shell-based operations to interact with Concourse CI infrastructure.
  • [EXTERNAL_DOWNLOADS]: The examples and the resource catalog reference numerous third-party Concourse resource types (e.g., cfcommunity/slack-notification-resource, aoldershaw/git-branches-resource). These are standard, widely-used community extensions in the Concourse ecosystem that are necessary for the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 7, 2026, 11:27 AM