release-workflow
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions specifically direct the agent to execute shell commands (
klistandcurl) to interface with the Red Hat Errata Tool API (errata.devel.redhat.com). This is implemented as a manual fallback because a dedicated tool is not available in the MCP server. While these interactions target well-known vendor infrastructure, instructions for raw shell execution increase the risk of command injection if parameters (like advisory IDs) are sourced from untrusted inputs. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a broad ingestion surface that could be exploited via indirect prompt injection.
- Ingestion points: The agent reads release state from YAML files in GitHub (
statebox/{release}.yaml), test result JSON files in GitHub (ocp-test-result-{build}-amd64.json), and API responses from the Errata Tool and Release Controller. - Boundary markers: The documentation does not specify the use of delimiters or 'ignore' instructions when processing these external data sources.
- Capability inventory: The skill provides access to 27 OAR-specific tools via MCP, as well as the ability to execute shell commands for Kerberos-authenticated API calls.
- Sanitization: There is no explicit requirement or description for sanitizing or validating the contents of the ingested JSON/YAML files before they influence the agent's decision logic (e.g., determining whether to 'Pass' or 'Fail' a gate check).
Audit Metadata