incident-responder

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data including application logs, user reports, and deployment diffs, creating a surface for indirect injection attacks.
  • Ingestion points: The skill reads application logs (/var/log/*), git logs, and user-provided incident context as specified in references/investigation-protocol.md and SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters used to separate untrusted log data from agent instructions, nor are there warnings to the agent to ignore embedded commands within the data.
  • Capability inventory: The skill has access to the Bash tool for running diagnostics, and Write/Edit tools for report generation, which could be exploited if the agent follows instructions found in logs.
  • Sanitization: There is no evidence of sanitization, filtering, or escaping of log content before it is processed by the model.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute a wide range of diagnostic commands across the operating system, databases, and container orchestrators.
  • Evidence: references/diagnostic-commands.md contains shell command templates for kubectl, psql, mysql, redis-cli, and standard Linux utilities like grep, awk, and lsof.
  • [DATA_EXFILTRATION]: While the skill does not show signs of active exfiltration, it is explicitly instructed to access and examine sensitive system paths and configuration files which could lead to unauthorized data exposure.
  • Evidence: references/investigation-protocol.md instructs the agent to examine environment variables, .env files, and secret rotations as part of the deployment check process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:02 PM
Security Audit — agent-trust-hub — incident-responder