ecc-claude-engineering-ci-cd-pipeline-builder
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by design.
- Ingestion points: Reads guidance from paths specified in
references/upstream-path.txt(targeting theupstream-import/directory). - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the workflow.
- Capability inventory: The workflow in
SKILL.mdexplicitly includes execution of tool-backed steps and verification of outcomes on the system. - Sanitization: No sanitization, validation, or escaping of the extracted guidance is defined before it is translated into executable steps.
- [COMMAND_EXECUTION]: The skill workflow is designed to dynamically translate text-based guidance into executable tool-backed steps, which involves runtime generation and execution of commands based on external file content.
Audit Metadata