ops-inspector

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references external source files and sibling skills hosted on cnb.cool. These resources are part of the Tencent ecosystem and are used for skill discovery and documentation.
  • [PROMPT_INJECTION]: An indirect prompt injection surface exists because the skill processes log data through tools like queryLogs and queryFunctions(action="listFunctionLogs"). Malicious content embedded in application logs could potentially influence the agent's analysis or subsequent actions during the diagnostic workflow.
  • Ingestion points: Cloud function logs, CloudRun logs, and CLS log search results (SKILL.md).
  • Boundary markers: None specified in the instructions for handling or delimiting log content during processing.
  • Capability inventory: Extensive read and query capabilities across cloud functions, CloudRun services, and multiple database types (PostgreSQL, MySQL, NoSQL).
  • Sanitization: No explicit sanitization, validation, or filtering of external log content before analysis is described in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 03:37 PM
Security Audit — agent-trust-hub — ops-inspector