operate-devops

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and act upon repository-hosted configuration files, which introduces a surface for indirect prompt injection.
  • Ingestion points: The workflow involves reading repository and environment guidance, CI/CD pipelines, and infrastructure-as-code files as described in SKILL.md and references/change-safety.md.
  • Boundary markers: The skill does not explicitly define markers to isolate data from instructions, but it mandates manual diff reviews and staged rollouts.
  • Capability inventory: The agent context implies the use of CLI tools for rendering, planning, and applying configuration changes.
  • Sanitization: Security is addressed through multi-stage verification, including linting, dry runs, and policy tests to detect anomalies in external configuration data.
  • [NO_CODE]: The skill consists exclusively of instructional Markdown and YAML configuration files. No scripts, binaries, or executable code are included in the skill distribution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 10:36 AM
Security Audit — agent-trust-hub — operate-devops