infrahub-analyst
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a standard operational tool designed for the Infrahub platform. All external documentation links point to the official Infrahub domain (docs.infrahub.app), which is consistent with the vendor's primary product. It provides clear guidance on using MCP tools for infrastructure management.
- [COMMAND_EXECUTION]: The skill provides patterns for using tools (
mcp__infrahub__infrahub_create,mcp__infrahub__infrahub_update) that can modify data within Infrahub. These operations are essential for the remediation use cases described in the documentation. The skill correctly advises performing these actions on a non-main branch to ensure review and safety. - [DATA_EXPOSURE]: The skill facilitates access to sensitive network configuration data, including IPAM (IP Address Management), BGP sessions, and device topologies. This access is limited to the connected Infrahub instance and is the intended purpose of the analyst skill.
- [PROMPT_INJECTION]: As the skill ingests data from external sources (the Infrahub database), there is a potential surface for indirect prompt injection if an attacker were to place malicious instructions inside Infrahub object attributes (e.g., device descriptions). However, the skill treats this data as information to be correlated rather than executable instructions, and the risk is considered low.
Audit Metadata