sop-maintenance

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCECOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill utilizes template placeholders such as {sop_paths}, {new_version}, and {summary of changes} to generate SOP content. This creates a surface for indirect prompt injection if data sourced from untrusted inputs is interpolated into these templates.
  • Ingestion points: The skill reads existing SOP files (SKILL.md) and processes user-provided values for placeholders.
  • Boundary markers: Absent; there are no delimiters or warnings to ignore instructions inside the interpolated text.
  • Capability inventory: The skill uses Write, Edit, Bash, Grep, and Glob tools to modify files and execute commands as defined in the frontmatter of SKILL.md.
  • Sanitization: Absent; no sanitization or validation logic is defined for the placeholder inputs.
  • [PERSISTENCE]: The skill documents how to set environment variables by modifying shell profiles (~/.zshrc and ~/.bashrc). Although intended for legitimate configuration of the AGENT_SOP_PATHS variable, instructions to modify shell startup files are associated with persistence mechanisms.
  • [COMMAND_EXECUTION]: The examples provided in the skill include the use of administrative and network tools, including kubectl for resource management (e.g., kubectl patch configmap, kubectl rollout restart) and curl for interacting with external monitoring endpoints (monitoring.example.com).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 03:06 AM
Security Audit — agent-trust-hub — sop-maintenance