incident-triage
Pass
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources including AWS CloudWatch alarms and CloudTrail event logs, which could theoretically contain malicious instructions.
- Ingestion points: Signal collection occurs through
aws cloudwatch describe-alarmsandaws cloudtrail lookup-eventsinSKILL.md. - Boundary markers: The skill uses a structured report format defined in
assets/incident-report-template.mdto present the data. - Capability inventory: The skill's active capabilities are restricted to read-only resource queries and report generation. High-risk actions like service restarts or configuration changes are documented as 'human-required' and not automated.
- Sanitization: There is no explicit sanitization for alarm names or event descriptions before they are included in the generated incident report.
Audit Metadata