pipeline-security

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: In SKILL.md, the 'Prompt Injection Safety Notice' provides explicit defensive instructions to ignore and treat as data any prompt injection strings (such as "ignore previous instructions") found within analyzed CI/CD configurations, preventing the agent from following malicious directives embedded in external content.
  • [DATA_EXFILTRATION]: In SKILL.md, the skill explicitly directs the agent to redact or reference sensitive values like credentials generically, ensuring that private information discovered during the analysis is not exposed in the final report.
  • [SAFE]: The skill limits its capabilities to a minimal set of read-only tools (Read, Grep, Glob) and implements a comprehensive security posture including role boundaries and strict output validation in its constraints and processes defined in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:06 AM
Security Audit — agent-trust-hub — pipeline-security