incident-response
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides procedures that involve running system-level diagnostic and mitigation commands to investigate outages or breaches. Detailed forensics and system state gathering are standard components of the incident response playbooks.
- Evidence:
references/triage.mdsuggests using commands likeps aux,ss -tulpn,sosreport -k, andkubectl logs --previousto capture system state. - Evidence:
references/mitigate.mdmentions forensic commands for disk imaging, log extraction, and network connection auditing. - [PRIVILEGE_ESCALATION]: The skill includes instructions for high-privilege operations related to security incident mitigation and credential management, which are required for isolating breaches.
- Evidence:
references/mitigate.mdcontains procedures for rotating all exposed credentials, revoking active sessions/tokens, and isolating hosts via cloud security group modifications. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze potentially untrusted external data such as system logs, error reports, and metrics to perform its tasks.
- Ingestion points: System logs (
auth/syslog/app), metric snapshots, and user-provided incident descriptions defined inreferences/triage.mdandreferences/mitigate.md. - Boundary markers: None explicitly defined in the instruction markdown.
- Capability inventory: The agent is configured with
bash,run_command,view_file,write_to_file,replace_file_content, andgrep_searchtools as seen inagents/openai.yamlandSKILL.md. - Sanitization: No explicit sanitization or filtering logic is provided for the external data being processed, relying on the agent's interpretation.
Audit Metadata