cohere-incident-runbook
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references official SDKs and documentation from Cohere, including links to official Python and TypeScript SDK repositories and the service status page.
- [COMMAND_EXECUTION]: Employs standard tools like Grep and Glob to analyze local project files and incident evidence, following a diagnostic approach constrained by read-only instructions during investigation.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted incident evidence. Ingestion points: incident records and application logs. Boundary markers: explicit instructions to ignore prompts or documents when generating bundles and to redact all sensitive information. Capability inventory: Write and Edit tools for mitigation, restricted to owner-approved actions. Sanitization: mandates redaction of customer identifiers and authorization headers in all outputs.
- [SAFE]: Includes robust security instructions regarding credential management, specifically forbidding the persistence or exposure of API keys and recommending the use of approved secret managers.
Audit Metadata