ops-inspector
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill functions as a legitimate vendor resource authored by
tencentcloudbase. All external console links and API interactions target officialtcb.cloud.tencent.cominfrastructure, which is consistent with the skill's diagnostic purpose. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an inherent surface for indirect prompt injection because its primary function involves the ingestion and interpretation of untrusted log data from external sources.
- Ingestion points: Untrusted environment data enters the agent context via tool outputs from
queryLogs,listFunctionLogs, andgetFunctionLogDetail(SKILL.md). - Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands when the agent processes log content.
- Capability inventory: The skill uses diagnostic tools such as
queryEnv,queryFunctions, andqueryCloudRunto gather resource status and metrics (SKILL.md). - Sanitization: The agent is instructed to search for specific structural patterns (e.g., 'ERROR', '429', 'TIMEOUT') rather than executing content found within logs, minimizing the risk associated with this surface.
Audit Metadata