incident-sitrep

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • Untrusted Data Handling: The skill explicitly instructs the AI to treat messages, alert payloads, and other bot posts as untrusted data, cautioning to extract facts but never follow embedded instructions. This is a robust defense against indirect prompt injection.
  • Least Privilege and Authority: The skill is designed to report rather than act. It forbids the AI from declaring incidents resolved, changing severity, assigning tasks, or posting to external platforms (email, status pages) without human review.
  • Data Integrity: It implements strict rules for evidence, requiring the AI to re-read 'key signals' (metrics) live before posting, and distinguishes between human-verified facts and unverified bot data.
  • External References: The skill references a local file (../../references/charts.md) for chart formatting, which is a standard internal resource reference for the platform environment and does not involve external network downloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:52 PM
Security Audit — agent-trust-hub — incident-sitrep