pulumi-stacks

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process Pulumi configuration files and metadata, which serves as a potential ingestion point for untrusted data if these files originate from external contributors or third-party repositories.
  • Ingestion points: Project files (Pulumi.yaml), environment-specific configuration files (Pulumi.dev.yaml, Pulumi.prod.yaml), and values retrieved via pulumi config or pulumi stack output.
  • Boundary markers: The instructions do not provide specific markers or safety warnings for the agent to treat values extracted from these files as untrusted content.
  • Capability inventory: The skill uses the Bash tool to execute pulumi CLI commands and the Read tool to access project files. These tools allow the agent to read and modify local file systems and potentially interact with cloud providers.
  • Sanitization: The provided code snippets demonstrate direct interpolation of configuration values into resource properties (e.g., Name: 'web-server-${environment}') without explicit sanitization or validation logic.
  • [COMMAND_EXECUTION]: The skill relies on the Bash tool to execute numerous pulumi CLI operations. While this is the intended primary purpose of the skill, it represents a surface for command injection if an agent were to pass unvalidated user input or malicious configuration values into shell commands like pulumi stack select or pulumi config set.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 09:01 AM
Security Audit — agent-trust-hub — pulumi-stacks