runpod
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from system and container logs, which is an attack surface for indirect prompt injection.
- Ingestion points: System and container logs read during diagnostics in
references/diagnostics-and-lifecycle.md. - Boundary markers: Directives in
SKILL.mdto query allowlists and avoid printing full environment objects. - Capability inventory: Shell operations via
runpodctland API interactions via GraphQL and REST. - Sanitization: Specific redaction instructions for API keys and secrets in
SKILL.mdandreferences/diagnostics-and-lifecycle.md. - [COMMAND_EXECUTION]: The skill uses the
runpodctlCLI tool for resource management. - Standard management commands such as
runpodctl userandrunpodctl pod listare documented. - Safety gates including inventory-first inventory and post-creation verification are used to manage risk.
Audit Metadata