replit-incident-runbook
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: Uses
curlandjqwithin a script to fetch platform status and probe application availability. The commands use strict security flags (--proto '=https',--max-filesize,--connect-timeout). - [EXTERNAL_DOWNLOADS]: Fetches status data from
https://status.replit.com/api/v2/summary.json. This is a well-known service provided by the vendor (Replit) and is documented for monitoring purposes. - [DATA_EXPOSURE]: The skill explicitly instructs users to redact evidence, avoid pasting secrets into logs or chat, and preserve tenant isolation, adhering to security best practices.
- [PROMPT_INJECTION]: No evidence of system prompt overrides or instruction bypass attempts found.
Audit Metadata