sop-maintenance
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCECOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill utilizes template placeholders such as
{sop_paths},{new_version}, and{summary of changes}to generate SOP content. This creates a surface for indirect prompt injection if data sourced from untrusted inputs is interpolated into these templates. - Ingestion points: The skill reads existing SOP files (
SKILL.md) and processes user-provided values for placeholders. - Boundary markers: Absent; there are no delimiters or warnings to ignore instructions inside the interpolated text.
- Capability inventory: The skill uses
Write,Edit,Bash,Grep, andGlobtools to modify files and execute commands as defined in the frontmatter ofSKILL.md. - Sanitization: Absent; no sanitization or validation logic is defined for the placeholder inputs.
- [PERSISTENCE]: The skill documents how to set environment variables by modifying shell profiles (
~/.zshrcand~/.bashrc). Although intended for legitimate configuration of theAGENT_SOP_PATHSvariable, instructions to modify shell startup files are associated with persistence mechanisms. - [COMMAND_EXECUTION]: The examples provided in the skill include the use of administrative and network tools, including
kubectlfor resource management (e.g.,kubectl patch configmap,kubectl rollout restart) andcurlfor interacting with external monitoring endpoints (monitoring.example.com).
Audit Metadata