lessons-learned
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided incident reports, timelines, and technical details, which creates a surface for indirect prompt injection where malicious instructions could be embedded in the incident data to influence the agent's behavior.
- Ingestion points: The skill ingests user-supplied content during Phase 1 (Incident Summary) and Phase 2 (Timeline Reconstruction) in SKILL.md.
- Boundary markers: The skill does not define explicit delimiters or use "ignore embedded instructions" warnings when processing the incident data.
- Capability inventory: The skill has the capability to write to the local file system to create new skill files (
~/.claude/skills/), modify project documentation (CLAUDE.md), and create automation scripts as described in Phase 5 and Phase 6. - Sanitization: There are no instructions or mechanisms for sanitizing or escaping the external incident content before it is interpolated into the fix implementation or documentation steps.
Audit Metadata