incident-postmortem

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional Markdown content intended to guide the agent in facilitating incident postmortems.
  • [NO_CODE]: There are no scripts, binaries, or shell commands included in the skill files. All implementation details are provided as Markdown examples or conceptual templates.
  • [DATA_EXFILTRATION]: No network operations (e.g., curl, wget, fetch) or sensitive data access patterns (e.g., accessing .ssh or .env files) were found.
  • [PROMPT_INJECTION]: The instructions in SKILL.md establish a persona and define scope using a reference system. These instructions do not attempt to override system safety guidelines or bypass AI constraints.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to analyze potentially untrusted user-provided incident data, it lacks any executable capabilities (such as file writes, network requests, or subprocess execution) that would make it vulnerable to exploitation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 04:54 PM
Security Audit — agent-trust-hub — incident-postmortem