ops-devops-platform

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill contains a Python script scripts/validate_sources.py designed to check the availability of documentation links. It performs network requests to well-known services and trusted documentation sources listed in data/sources.json. No sensitive information is shared during these operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill features an inherent vulnerability surface for indirect prompt injection through its learning mechanism.
  • Ingestion points: SKILL.md directs the agent to read learnings.consolidated.md and learnings.md at runtime.
  • Boundary markers: Content is read without specific isolation markers or instructions to disregard potential commands in the logs.
  • Capability inventory: The skill references agents-skills-feedback-loop/scripts/append_learning.py for persistent file writing to update the learning log.
  • Sanitization: Content appended to the learnings files is not sanitized by the skill's provided assets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — ops-devops-platform