promovaweb-devops-review-redis-stack
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a legitimate administrative tool for auditing Docker Swarm stack configurations. Its operations are local and limited to reading text files and writing a markdown report.
- [PROMPT_INJECTION]: The skill reads external configuration files (
redis.yaml,n8n.yaml,chatwoot.yaml), which constitutes an indirect prompt injection surface. However, the risk is negligible as the skill lacks capabilities for code execution or network exfiltration. - Ingestion points: The skill reads project configuration files (
redis.yaml,n8n.yaml,chatwoot.yaml) from the local file system. - Boundary markers: None present in the instructions to delimit audited content from system instructions.
- Capability inventory: The skill is restricted to file reading and generating a report in
redis.audit.md. - Sanitization: No sanitization or safety-filtering is applied to the ingested YAML data.
Audit Metadata