operate-devops
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and act upon repository-hosted configuration files, which introduces a surface for indirect prompt injection.
- Ingestion points: The workflow involves reading repository and environment guidance, CI/CD pipelines, and infrastructure-as-code files as described in SKILL.md and references/change-safety.md.
- Boundary markers: The skill does not explicitly define markers to isolate data from instructions, but it mandates manual diff reviews and staged rollouts.
- Capability inventory: The agent context implies the use of CLI tools for rendering, planning, and applying configuration changes.
- Sanitization: Security is addressed through multi-stage verification, including linting, dry runs, and policy tests to detect anomalies in external configuration data.
- [NO_CODE]: The skill consists exclusively of instructional Markdown and YAML configuration files. No scripts, binaries, or executable code are included in the skill distribution.
Audit Metadata