discover-infrastructure

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a structured interviewer and documentation tool. It interacts with the user to gather technical data and writes that data to the local filesystem in a designated project structure. Analysis found no evidence of exfiltration, malicious command execution, or persistence mechanisms.
  • [PROMPT_INJECTION]: The skill includes a capability to ingest external documents provided by the user (Step 1: Adaptive Behavior). This creates a surface for indirect prompt injection, where an attacker could place malicious instructions inside a CMDB export or architecture document to influence the agent's behavior. However, the skill's capabilities are limited to generating markdown reports, which significantly reduces the risk of such an injection leading to system-level impact.
  • [COMMAND_EXECUTION]: The skill instructions contain no shell commands, scripts, or system-level execution patterns. It relies entirely on natural language instructions and local file manipulation for its operations.
  • [DATA_EXFILTRATION]: While the skill requests sensitive information (e.g., networking topology and identity providers), this data collection is the primary stated purpose of the skill. No network operations or external endpoints were detected that would allow this data to be exfiltrated from the local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 06:30 PM
Security Audit — agent-trust-hub — discover-infrastructure