deployment-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes an agent that processes external configuration files (e.g., Jenkinsfiles, GitHub Actions YAML, Kubernetes manifests) and deployment logs, creating an attack surface for indirect prompt injection.\n
- Ingestion points: Reads repository contents, CI/CD pipeline definitions, and deployment logs across various files.\n
- Boundary markers: The skill does not provide instructions for the agent to use delimiters or treat external data as untrusted.\n
- Capability inventory: Significant capabilities including infrastructure provisioning, container orchestration, and secrets management.\n
- Sanitization: No mention of input validation or sanitization for ingested configuration data.\n- [NO_CODE]: The skill is entirely documentation-based and does not include any executable scripts, binaries, or active command-line instructions.
Audit Metadata