skills/nuonco/skills/nuon-app-config/Gen Agent Trust Hub

nuon-app-config

Pass

Audited by Gen Agent Trust Hub on Mar 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The configuration templates reference initialization scripts and sandbox modules hosted on the vendor's official GitHub repositories (github.com/nuonco/*). Evidence: 'init_script_url' in 'references/component-templates.md' and sandbox repo references in 'SKILL.md'.\n- [COMMAND_EXECUTION]: The skill generates TOML files containing shell scripts (Action Scripts) and Kubernetes manifests intended for execution within a customer's cloud environment. The default templates assign the 'AdministratorAccess' managed policy to the IAM roles used for provisioning and maintenance. Evidence: 'permissions/' directory structure and 'actions/' definitions in 'SKILL.md' and 'references/example-mattermost.md'.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it interpolates user responses into executable scripts.\n
  • Ingestion points: Data is collected through a structured discovery interview in 'SKILL.md'.\n
  • Boundary markers: No explicit delimiters are used to wrap interpolated variables in the generated TOML.\n
  • Capability inventory: The generated output includes shell scripts ('actions/') and manifests ('components/') with cluster management capabilities via 'kubectl'.\n
  • Sanitization: No sanitization or validation is applied to user-provided strings before they are inserted into 'inline_contents' or manifest 'stringData'.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 12, 2026, 09:59 PM
Security Audit — agent-trust-hub — nuon-app-config