alert-investigation
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a systematic SRE methodology for alert triage, impact assessment, and root cause analysis. All operations use the 'observe' CLI, which is consistent with the vendor's (observeinc) ecosystem.
- [SAFE]: The mandatory instruction to run 'observe skill view' is used to synchronize the skill's context from the platform's own repository.
- [SAFE]: No evidence of data exfiltration, credential theft, or unauthorized remote code execution was detected.
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it processes external alert and log data. 1. Ingestion points: Alert details, monitor values, and log datasets (SKILL.md). 2. Boundary markers: Absent; there are no specific delimiters to separate untrusted data from instructions. 3. Capability inventory: Metric querying, log searching, and knowledge graph resolution. 4. Sanitization: Absent; the skill does not specify filtering or escaping for retrieved data before analysis.
Audit Metadata