render-env-vars
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized access attempts were identified. The skill contains legitimate instructional content for platform configuration.
- [INDIRECT_PROMPT_INJECTION]: The skill describes a potential surface for indirect prompt injection as it facilitates the configuration of environment variables and secrets, though no executable risk is identified.
- Ingestion points: User-provided environment variable values, secret file content, and environment group definitions mentioned in SKILL.md and references/wiring-reference.md.
- Boundary markers: The instructions do not specify delimiters or markers to isolate environment variable values from the agent's instructions.
- Capability inventory: No executable scripts, subprocess calls, or network operations are included in the skill files.
- Sanitization: The skill does not provide instructions for the agent to sanitize or validate the content of the environment variables it processes.
Audit Metadata