postmortem
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions define a purely analytical workflow for causal reasoning and documentation without network access or sensitive data exfiltration capabilities.
- [COMMAND_EXECUTION]: The skill includes a local validation script (scripts/validate.sh) that performs static string matching on internal skill files to ensure the configuration adheres to the defined 'postmortem' contract. This is a restricted, benign administrative action.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests 'verdict' data files (.agents/ao/verdicts/) for analysis. While the skill lacks explicit boundary markers or data sanitization, the analytical framework requiring mechanism descriptions and counterfactual tests acts as a logical control. The capability set is limited to local file writes and integrity-check scripts.
Audit Metadata