it-ops-orchestrator

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of instructional text for task routing and orchestration. It does not contain any executable scripts, shell commands, or external dependencies.
  • [INDIRECT_PROMPT_INJECTION]: The skill functions as an orchestrator that aggregates data from users and other specialist agents, creating an ingestion surface for potentially untrusted data. 1. Ingestion points: The skill processes broadly stated user IT requirements and integrates outputs from multiple specialist skills such as powershell-expert and azure-infra-engineer. 2. Boundary markers: The instructions mandate establishing clear scope boundaries for each specialist and maintaining context consistency to prevent contradictory guidance. 3. Capability inventory: The skill's capabilities are limited to documentation, task decomposition, and routing; direct execution of PowerShell or Azure operations is explicitly restricted. 4. Sanitization: The orchestration logic requires the agent to validate specialist responses for completeness and ensure all solutions follow organizational security and governance policies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 08:06 AM
Security Audit — agent-trust-hub — it-ops-orchestrator