pipeline-security
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: In SKILL.md, the 'Prompt Injection Safety Notice' provides explicit defensive instructions to ignore and treat as data any prompt injection strings (such as "ignore previous instructions") found within analyzed CI/CD configurations, preventing the agent from following malicious directives embedded in external content.
- [DATA_EXFILTRATION]: In SKILL.md, the skill explicitly directs the agent to redact or reference sensitive values like credentials generically, ensuring that private information discovered during the analysis is not exposed in the final report.
- [SAFE]: The skill limits its capabilities to a minimal set of read-only tools (Read, Grep, Glob) and implements a comprehensive security posture including role boundaries and strict output validation in its constraints and processes defined in SKILL.md.
Audit Metadata