runbook

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to process user-supplied arguments and data retrieved from external connectors (like knowledge bases or ITSM systems) to populate runbook templates, creating a surface where untrusted content could influence agent behavior. (1) Ingestion points: Data enters the agent context via $ARGUMENTS and connected systems such as ~~knowledge base and ~~ITSM. (2) Boundary markers: The skill instructions do not specify the use of delimiters or 'ignore' instructions to distinguish between the prompt instructions and the ingested external content. (3) Capability inventory: The agent using this skill typically has access to tools for writing files, performing network operations to publish to wikis, and interacting with incident management platforms. (4) Sanitization: There are no instructions provided for sanitizing or validating external data before it is interpolated into the runbook template.
  • Command Generation Pattern: The skill encourages the documentation of precise CLI commands for operational procedures. While intended for administrative use, these commands should be reviewed to ensure they have not been influenced by malicious content within the external data sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:26 PM