incident-triage-runbook

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Operational Data Processing]: The skill instructs the agent to ingest and analyze external data sources, specifically production logs and code diffs. This is a necessary component of incident triage, though it creates a surface area for indirect prompt injection if those logs or diffs contain malicious text intended to influence the agent. In the context of SRE tasks, this is an expected behavior and the skill includes specific instructions to focus on timestamps and known issues rather than open-ended 'fishing'.
  • [Credential and Secret Handling]: The runbook asks for a commit SHA as a root cause identifier and references service names like 'stripe-api' or 'db-primary'. These are standard identifiers and do not involve hardcoded credentials, sensitive tokens, or unsafe secret management practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 07:40 PM
Security Audit — agent-trust-hub — incident-triage-runbook