postmortem
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, which creates a potential surface for indirect prompt injection attacks.
- Ingestion points: Instructions in
SKILL.md(Step 1) andresources/template.mddirect the agent to gather facts from potentially untrusted sources like system logs, metrics, and witness accounts. - Boundary markers: The skill lacks explicit instructions or delimiters to help the agent distinguish between data to be analyzed and instructions to be followed within those data sources.
- Capability inventory: The skill's potential for harm is strictly limited as it contains no capabilities for network operations, arbitrary shell command execution, or writing to sensitive file system locations.
- Sanitization: There are no mentioned mechanisms for sanitizing, validating, or filtering the content of the external logs or reports before they are processed by the agent.
Audit Metadata