ops-inspector

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill functions as a legitimate vendor resource authored by tencentcloudbase. All external console links and API interactions target official tcb.cloud.tencent.com infrastructure, which is consistent with the skill's diagnostic purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an inherent surface for indirect prompt injection because its primary function involves the ingestion and interpretation of untrusted log data from external sources.
  • Ingestion points: Untrusted environment data enters the agent context via tool outputs from queryLogs, listFunctionLogs, and getFunctionLogDetail (SKILL.md).
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands when the agent processes log content.
  • Capability inventory: The skill uses diagnostic tools such as queryEnv, queryFunctions, and queryCloudRun to gather resource status and metrics (SKILL.md).
  • Sanitization: The agent is instructed to search for specific structural patterns (e.g., 'ERROR', '429', 'TIMEOUT') rather than executing content found within logs, minimizing the risk associated with this surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 09:21 AM
Security Audit — agent-trust-hub — ops-inspector