it-ops-orchestrator
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists entirely of instructional text for task routing and orchestration. It does not contain any executable scripts, shell commands, or external dependencies.
- [INDIRECT_PROMPT_INJECTION]: The skill functions as an orchestrator that aggregates data from users and other specialist agents, creating an ingestion surface for potentially untrusted data. 1. Ingestion points: The skill processes broadly stated user IT requirements and integrates outputs from multiple specialist skills such as powershell-expert and azure-infra-engineer. 2. Boundary markers: The instructions mandate establishing clear scope boundaries for each specialist and maintaining context consistency to prevent contradictory guidance. 3. Capability inventory: The skill's capabilities are limited to documentation, task decomposition, and routing; direct execution of PowerShell or Azure operations is explicitly restricted. 4. Sanitization: The orchestration logic requires the agent to validate specialist responses for completeness and ensure all solutions follow organizational security and governance policies.
Audit Metadata