incident-commander
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a comprehensive suite of incident management utilities including severity scoring and post-mortem generation. All scripts (incident_classifier.py, timeline_reconstructor.py, etc.) utilize only the Python standard library and do not perform any network operations.
- [PROMPT_INJECTION]: The instructions in SKILL.md and documentation do not contain any patterns attempting to override agent behavior, bypass safety filters, or extract system prompts.
- [DATA_EXFILTRATION]: No sensitive file paths, credential exfiltration patterns, or network communication tools were found. The scripts process data provided via standard input or local files without external transmission.
- [REMOTE_CODE_EXECUTION]: No remote script execution, package installations from untrusted sources, or dynamic code execution patterns (like eval or exec on user input) were detected.
- [OBFUSCATION]: The code and documentation are written in plain text. No Base64 encoding of commands, zero-width characters, or homoglyph-based URL obfuscation were found.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes incident data at runtime, it does not possess capabilities (like shell execution or network writes) that would allow for exploitation via indirect injection.
- Ingestion points: Incident data ingested via stdin or JSON files in scripts/incident_classifier.py and scripts/timeline_reconstructor.py.
- Boundary markers: The SKILL.md utilizes a 'Clarify First' section to ensure input data is well-defined before processing.
- Capability inventory: No subprocess calls, network access, or write capabilities to system directories are present in the provided scripts.
- Sanitization: Ingested data is parsed using standard json.loads and string normalization with no dangerous sinks.
Audit Metadata