cicd-architecture-auditor
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: CRITICALINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and analyzing untrusted GitHub Actions workflow files (.yml / .yaml) shared by the user. This creates a surface for potential indirect prompt injection attacks if the input files contain malicious instructions masked as comments or configuration data.
- Ingestion points: Workflow files provided by users for performance and security audits (documented in SKILL.md).
- Boundary markers: The skill does not currently define specific delimiters or instructions for the agent to isolate and ignore embedded commands within the analyzed data.
- Capability inventory: The agent generates complete, executable GHA workflows and suggests administrative commands (e.g., sudo apt-get install) as part of its remediation guidelines.
- Sanitization: No explicit input validation or sanitization rules are provided to the agent for processing external workflow content.
- [EXTERNAL_DOWNLOADS]: The skill provides templates that reference official GitHub Actions and well-known community actions to implement best practices for Flutter delivery.
- Evidence: References to 'actions/checkout@v4', 'subosito/flutter-action@v2', 'actions/cache@v4', and 'webfactory/ssh-agent@v0.9.0' are used to facilitate standard CI/CD operations such as dependency caching and secret management. These are well-established tools within the GitHub Actions ecosystem.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata