using-devops-engineering

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily a collection of markdown reference documents providing technical guidance on DevOps practices. It does not contain executable scripts or hidden logic.
  • [EXTERNAL_DOWNLOADS]: The skill includes documentation examples that reference trusted organizations and well-known services, such as Google (gcr.io), Chainguard (cgr.dev), and standard GitHub repositories for open-source tools like Argo CD and OpenTofu. These are recognized as safe and reputable sources within the developer ecosystem.
  • [PROMPT_INJECTION]: No malicious prompt injection patterns were found. The instructions are focused on routing the AI to the appropriate technical specialist sheets to improve the accuracy of its operational advice.
  • [DATA_EXFILTRATION]: The skill provides best-practice advice on secrets management, emphasizing the use of vaults and the avoidance of hardcoded credentials. No hardcoded secrets or exfiltration patterns were detected in the skill itself.
  • [COMMAND_EXECUTION]: The skill contains various code snippets (YAML, Bash, Dockerfile) used as templates and examples for the agent's internal reasoning. These are not used for direct, unvalidated execution on the host system.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 08:34 PM
Security Audit — agent-trust-hub — using-devops-engineering