incident-to-prompt
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of markdown instructions without any executable scripts, command line operations, or external dependencies.
- [PROMPT_INJECTION]: Instructions include clear defensive boundaries that explicitly prohibit the generation of exploit payloads and require human approval for high-risk modifications.
- [DATA_EXPOSURE]: Operational guardrails specifically forbid the uploading of private source code or secrets to external systems, mitigating risk of sensitive data exposure.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (security incidents and vulnerability reports), creating an indirect injection surface. Ingestion points: User-provided incident patterns and vulnerability data in SKILL.md. Boundary markers: None identified. Capability inventory: No tool usage or command execution capabilities are defined within the skill. Sanitization: Not performed; the skill generates documentation and prompts based on the input.
Audit Metadata