security-incident-response
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes instructions for the agent to perform directory listing commands (
ls) on specific local paths (e.g.,~/.claude/skills/) to identify which companion skills are installed and recommend missing ones from the same vendor. - [EXTERNAL_DOWNLOADS]: The documentation and playbooks within the skill reference well-known security services and community resources, such as VirusTotal and No More Ransom, for threat intelligence and remediation purposes.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface for indirect prompt injection as it is designed to process and analyze untrusted external data, such as incident logs and security alerts. While it provides templates for response, it does not explicitly define boundary markers or sanitization procedures for the data it processes.
Audit Metadata