devops-infra-orchestrator

Warn

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill implements a dynamic loading pattern where it reads and executes instructions from computed local filesystem paths (~/.agents/skill-clusters/skills/<spoke-name>/SKILL.md) based on user-supplied intent. Furthermore, the orchestrator facilitates high-privilege operations including the use of the uc CLI for cluster management, modifying OS firewall rules via the healthcheck spoke, and executing configuration changes on enterprise network devices.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it processes untrusted external data, specifically live URLs and web content, via the canary-watch spoke. Malicious instructions embedded in the metadata or content of checked URLs could potentially influence the agent's behavior.
  • Ingestion points: External HTTP/SSE content and live URLs processed during post-deployment verification.
  • Boundary markers: Absent. The orchestrator does not define explicit delimiters or instructions to ignore embedded commands when processing external site data.
  • Capability inventory: Execution of the uc CLI, network configuration via SSH/Netmiko, and host security remediation (firewall/ports).
  • Sanitization: Absent. There is no evidence of input validation, sanitization, or escaping for the data retrieved from external URLs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 22, 2026, 06:55 AM