doca-bf4-deployment
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves the agent processing output from external BMC tools and serial consoles, which represents a potential injection surface if the BMC or console stream were compromised.
- Ingestion points: Data enters the agent context via the serial console client output, Redfish Task resource polling, and pldmtool execution results.
- Boundary markers: There are no specific delimiters or instructions provided to isolate these external data streams from the agent's core instructions.
- Capability inventory: The skill enables the agent to guide high-risk shell commands including firmware updates, power cycles, and OS installations.
- Sanitization: No explicit sanitization or validation of the data ingested from the BMC tools is mentioned.
- [COMMAND_EXECUTION]: The skill provides detailed guidance for executing potentially destructive and irreversible hardware operations like firmware burns and factory resets.
- Evidence: Procedures are provided for PLDM firmware updates and ISO reflashing.
- Mitigation: The skill implements mitigation by requiring explicit user confirmation for each step and mandating the use of the doca-hardware-safety skill.
Audit Metadata