pulumi
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides detailed guidance for optimizing Pulumi resource graphs and state management using official and industry-standard patterns.
- [SAFE]: Secret handling guidelines correctly advocate for using Pulumi's built-in encryption and integration with external secret managers like HashiCorp Vault to prevent credential exposure.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed for agents to review and refactor infrastructure code. This task involves processing untrusted external data (Pulumi project files), which represents a surface for indirect prompt injection. 1. Ingestion points: Agent reads user-provided Pulumi TypeScript and YAML files (SKILL.md). 2. Boundary markers: None explicitly defined in the instructions to separate code from rules. 3. Capability inventory: Mentions use of Pulumi Automation API, command execution, and network requests (multiple rule files). 4. Sanitization: Not applicable to the skill's own logic.
Audit Metadata