ecc-claude-engineering-ci-cd-pipeline-builder

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by design.
  • Ingestion points: Reads guidance from paths specified in references/upstream-path.txt (targeting the upstream-import/ directory).
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the workflow.
  • Capability inventory: The workflow in SKILL.md explicitly includes execution of tool-backed steps and verification of outcomes on the system.
  • Sanitization: No sanitization, validation, or escaping of the extracted guidance is defined before it is translated into executable steps.
  • [COMMAND_EXECUTION]: The skill workflow is designed to dynamically translate text-based guidance into executable tool-backed steps, which involves runtime generation and execution of commands based on external file content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 04:46 PM
Security Audit — agent-trust-hub — ecc-claude-engineering-ci-cd-pipeline-builder