ops-nuke-cicd

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured guidance for NUKE build automation without any detected security vulnerabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and refactor repository-local files such as global.json, Build.cs, and project files.
  • Ingestion points: The skill reads repository configuration and build scripts (e.g., SKILL.md workflow step 1).
  • Boundary markers: None explicitly mentioned to separate untrusted repo data from instructions.
  • Capability inventory: Extensive build and shell execution capabilities including DotNetTasks, DockerTasks, and ProcessTasks.StartProcess (found in assets/nuke-target-template-build-test.cs and references/test-platform-modes-and-cli.md).
  • Sanitization: No explicit sanitization of repository content before processing.
  • [EXTERNAL_DOWNLOADS]: The skill references several external tools and documentation sources, all targeting trusted organizations or well-known services.
  • Fetches SBOM generation guidance from Microsoft's official GitHub repository (microsoft/sbom-tool).
  • References artifact attestation patterns from GitHub's official documentation.
  • Links to official NUKE, Microsoft, and Docker documentation and repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — ops-nuke-cicd