incident-triage

Pass

Audited by Gen Agent Trust Hub on Oct 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources including AWS CloudWatch alarms and CloudTrail event logs, which could theoretically contain malicious instructions.
  • Ingestion points: Signal collection occurs through aws cloudwatch describe-alarms and aws cloudtrail lookup-events in SKILL.md.
  • Boundary markers: The skill uses a structured report format defined in assets/incident-report-template.md to present the data.
  • Capability inventory: The skill's active capabilities are restricted to read-only resource queries and report generation. High-risk actions like service restarts or configuration changes are documented as 'human-required' and not automated.
  • Sanitization: There is no explicit sanitization for alarm names or event descriptions before they are included in the generated incident report.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 7, 2026, 05:00 AM