promovaweb-devops-review-redis-stack

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate administrative tool for auditing Docker Swarm stack configurations. Its operations are local and limited to reading text files and writing a markdown report.
  • [PROMPT_INJECTION]: The skill reads external configuration files (redis.yaml, n8n.yaml, chatwoot.yaml), which constitutes an indirect prompt injection surface. However, the risk is negligible as the skill lacks capabilities for code execution or network exfiltration.
  • Ingestion points: The skill reads project configuration files (redis.yaml, n8n.yaml, chatwoot.yaml) from the local file system.
  • Boundary markers: None present in the instructions to delimit audited content from system instructions.
  • Capability inventory: The skill is restricted to file reading and generating a report in redis.audit.md.
  • Sanitization: No sanitization or safety-filtering is applied to the ingested YAML data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 04:37 PM