skills/nicepkg/ai-workflow/postmortem/Gen Agent Trust Hub

postmortem

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of instructional documentation and templates for conducting incident reviews and postmortems. It does not contain any executable scripts, remote dependencies, or suspicious commands.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external incident data (e.g., logs, transcripts), which is an attack surface for indirect prompt injection. However, this is inherent to the analysis task, and no automated tools for fetching or executing such data are included within the skill.\n
  • Ingestion points: Incident reports, logs, and communication data referenced in SKILL.md and resources/template.md.\n
  • Boundary markers: The instructions do not define specific delimiters to separate untrusted data from instructions.\n
  • Capability inventory: The skill documentation does not leverage any internal or external tools.\n
  • Sanitization: No validation or sanitization procedures for external incident data are defined in the methodology.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:06 AM
Security Audit — agent-trust-hub — postmortem