ledger

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection due to its processing of untrusted external data combined with its ability to generate significant downstream configurations.
  • Ingestion points: The skill ingests infrastructure-as-code (IaC) resource definitions (Terraform, CloudFormation, Pulumi) and cloud utilization metrics (CPU, Memory, GPU) from external environments.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when parsing these external data sources.
  • Capability inventory: The skill generates actionable outputs including IaC modifications for the Scaffold agent, cost anomaly alert rules for the Beacon agent, and CI/CD gate specifications for the Gear agent.
  • Sanitization: There are no documented procedures for sanitizing or validating the content of ingested IaC code or metrics to prevent malicious instructions from influencing the agent's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:56 AM
Security Audit — agent-trust-hub — ledger