resurrection
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses role-play metaphors (referring to the process as a 'spell' and the documentation as a 'grimoire'). These are used for branding and do not attempt to bypass safety filters or override system constraints.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute restoration steps on systems. It includes a strong safety guardrail requiring explicit user confirmation before taking live actions that change access or touch system boundaries.
- [DATA_EXFILTRATION]: Instructions include assessing backups, logs, and configuration fragments. While this involves sensitive data access, it is the primary stated purpose of the skill (recovery) and no external network exfiltration patterns were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data sources (backups, logs, and system artifacts). This creates a potential surface where malicious instructions hidden in those files could influence the agent during the restoration process.
- Ingestion points: Reads backups, artifacts, logs, snapshots, and configuration fragments (SKILL.md).
- Boundary markers: Uses a confirmation gate before live actions (Procedure step 6).
- Capability inventory: Restoring systems, changing permissions, and executing restoration steps.
- Sanitization: Relies on assessment and verification but does not specify automated sanitization of log content.
Audit Metadata