pulumi-stacks
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process Pulumi configuration files and metadata, which serves as a potential ingestion point for untrusted data if these files originate from external contributors or third-party repositories.
- Ingestion points: Project files (
Pulumi.yaml), environment-specific configuration files (Pulumi.dev.yaml,Pulumi.prod.yaml), and values retrieved viapulumi configorpulumi stack output. - Boundary markers: The instructions do not provide specific markers or safety warnings for the agent to treat values extracted from these files as untrusted content.
- Capability inventory: The skill uses the
Bashtool to executepulumiCLI commands and theReadtool to access project files. These tools allow the agent to read and modify local file systems and potentially interact with cloud providers. - Sanitization: The provided code snippets demonstrate direct interpolation of configuration values into resource properties (e.g.,
Name: 'web-server-${environment}') without explicit sanitization or validation logic. - [COMMAND_EXECUTION]: The skill relies on the
Bashtool to execute numerouspulumiCLI operations. While this is the intended primary purpose of the skill, it represents a surface for command injection if an agent were to pass unvalidated user input or malicious configuration values into shell commands likepulumi stack selectorpulumi config set.
Audit Metadata