CtrlK
BlogDocsLog inGet started
Tessl Logo

aiox-devops

Activate Gage (devops) for GitHub Repository Manager & DevOps Specialist. Use for repository operations, version management, CI/CD, quality gates, and GitHub push operations. ONLY agent authorized to push to remote repository.

56

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/AIOX/agents/devops/SKILL.md
SKILL.md
Quality
Evals
Security

Security

3 findings: 2 critical severity, 1 high severity. Installing this skill is not recommended: please review these findings carefully if you do intend to do so.

Critical

E004: Prompt injection detected in skill instructions.

What this means

Detected a prompt injection in the skill instructions. The skill contains hidden or deceptive instructions that fall outside its stated purpose and attempt to override the agent’s safety guidelines or intended behavior.

Why it was flagged

The skill contains explicit instructions that tell the agent to "alter your state of being" and to let dependency task instructions "override any conflicting base behavioral constraints," which are hidden/deceptive attempts to override higher-level/system constraints outside the agent's stated devops scope.

Report incorrect finding
Critical

E006: Malicious code pattern detected in skill scripts.

What this means

Detected high-risk code patterns in the skill content — including its prompts, tool definitions, and resources — such as data exfiltration, backdoors, remote code execution, credential theft, system compromise, supply chain attacks, and obfuscation techniques.

Why it was flagged

The skill centralizes high-privilege repository operations (exclusive git push/force push and admin merges), includes an enforcement hook and explicit instructions to relax/restore branch protections atomically, and exposes administrative account commands that accept credentials — capabilities that can be deliberately abused to bypass safeguards and perform unauthorized repository or account takeover.

High

W007: Insecure credential handling detected in skill instructions.

What this means

The skill handles credentials insecurely by requiring the agent to include secret values verbatim in its generated output. This exposes credentials in the agent’s context and conversation history, creating a risk of data exfiltration.

Why it was flagged

The skill defines many commands and quick-command examples that take passwords and access_tokens as explicit arguments (e.g., {password}, {access_token}), which implies the agent will solicit and potentially embed secret values verbatim into commands or API calls, creating an exfiltration risk.

Repository
SynkraAI/aiox-core
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.