gear
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill documents and promotes security best practices for DevOps, including supply-chain defense, container hardening, and GitHub Actions security. It specifically warns against common attack vectors like hardcoded secrets, root containers, and unpinned dependencies. It also provides guidance on OIDC and SHA-pinning to prevent unauthorized access and supply chain compromise.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an inherent attack surface by ingesting and processing developer configuration files (e.g., package.json, Dockerfiles, GitHub Actions YAML). Mandatory Evidence Chain: (1) Ingestion points: Config files like package.json, turbo.json, and GHA workflows are used for build and audit tasks. (2) Boundary markers: The skill instructs users to use env: blocks and quote variables to avoid shell injection from untrusted data like PR titles. (3) Capability inventory: The agent can execute build commands, audits, and perform file system writes for configuration management. (4) Sanitization: The skill recommends avoiding direct interpolation of untrusted data into shell code and using explicit masking for secrets.
- [EXTERNAL_DOWNLOADS]: The skill references installation scripts for legitimate developer tools like Bun from their official and well-known domains (bun.sh). These references are standard for the tool's domain and do not represent a security risk under the trusted source guidelines.
Audit Metadata