instantly-migration-deep-dive

Pass

Audited by Gen Agent Trust Hub on Mar 12, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @instantly/sdk package via the npm package manager, which is a standard dependency for integrating with the Instantly platform.
  • [COMMAND_EXECUTION]: Utilizes kubectl to manage Kubernetes deployments, specifically for updating environment variables and performing rollouts during the migration and rollback phases.
  • [PROMPT_INJECTION]: Identifies an indirect prompt injection surface where the skill analyzes local source code using find and grep commands. Ingestion points: File content located within the user's codebase (SKILL.md). Boundary markers: Absent. Capability inventory: Tools for file writing, editing, and bash execution are available to the agent. Sanitization: No explicit validation or filtering is performed on the data retrieved from the codebase files.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 12, 2026, 06:45 PM