release-workflow

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions specifically direct the agent to execute shell commands (klist and curl) to interface with the Red Hat Errata Tool API (errata.devel.redhat.com). This is implemented as a manual fallback because a dedicated tool is not available in the MCP server. While these interactions target well-known vendor infrastructure, instructions for raw shell execution increase the risk of command injection if parameters (like advisory IDs) are sourced from untrusted inputs.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a broad ingestion surface that could be exploited via indirect prompt injection.
  • Ingestion points: The agent reads release state from YAML files in GitHub (statebox/{release}.yaml), test result JSON files in GitHub (ocp-test-result-{build}-amd64.json), and API responses from the Errata Tool and Release Controller.
  • Boundary markers: The documentation does not specify the use of delimiters or 'ignore' instructions when processing these external data sources.
  • Capability inventory: The skill provides access to 27 OAR-specific tools via MCP, as well as the ability to execute shell commands for Kerberos-authenticated API calls.
  • Sanitization: There is no explicit requirement or description for sanitizing or validating the contents of the ingested JSON/YAML files before they influence the agent's decision logic (e.g., determining whether to 'Pass' or 'Fail' a gate check).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 06:02 AM