cicd-architecture-auditor

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: CRITICALINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and analyzing untrusted GitHub Actions workflow files (.yml / .yaml) shared by the user. This creates a surface for potential indirect prompt injection attacks if the input files contain malicious instructions masked as comments or configuration data.
  • Ingestion points: Workflow files provided by users for performance and security audits (documented in SKILL.md).
  • Boundary markers: The skill does not currently define specific delimiters or instructions for the agent to isolate and ignore embedded commands within the analyzed data.
  • Capability inventory: The agent generates complete, executable GHA workflows and suggests administrative commands (e.g., sudo apt-get install) as part of its remediation guidelines.
  • Sanitization: No explicit input validation or sanitization rules are provided to the agent for processing external workflow content.
  • [EXTERNAL_DOWNLOADS]: The skill provides templates that reference official GitHub Actions and well-known community actions to implement best practices for Flutter delivery.
  • Evidence: References to 'actions/checkout@v4', 'subosito/flutter-action@v2', 'actions/cache@v4', and 'webfactory/ssh-agent@v0.9.0' are used to facilitate standard CI/CD operations such as dependency caching and secret management. These are well-established tools within the GitHub Actions ecosystem.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 18, 2026, 12:24 PM
Security Audit — agent-trust-hub — cicd-architecture-auditor