skills/happy-technologies-llc/happy-platform-skills/secops-incident-summarization/Gen Agent Trust Hub
secops-incident-summarization
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows standard procedures for security incident reporting within the ServiceNow ecosystem. No malicious patterns, obfuscation, or unauthorized data exfiltration attempts were detected.
- [DATA_EXPOSURE]: The skill accesses sensitive organizational information, including security incident logs, threat indicators (IOCs), and configuration management database (CMDB) asset details. This access is necessary for the stated purpose of summarization and is conducted through authorized service tools (MCP and REST).
- [COMMAND_EXECUTION]: The skill configuration allows the use of the
Bashtool; however, the provided instructions do not use it, and no suspicious command patterns or argument injections were identified in the procedure. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources (incident records and work notes) which could contain untrusted input. While the current instructions do not include boundary markers for this data, the skill's capabilities are focused on summarization and internal writing (Work Notes), presenting a low risk of malicious instruction execution.
Audit Metadata