incident-responder
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data including application logs, user reports, and deployment diffs, creating a surface for indirect injection attacks.
- Ingestion points: The skill reads application logs (
/var/log/*), git logs, and user-provided incident context as specified inreferences/investigation-protocol.mdandSKILL.md. - Boundary markers: There are no explicit instructions or delimiters used to separate untrusted log data from agent instructions, nor are there warnings to the agent to ignore embedded commands within the data.
- Capability inventory: The skill has access to the
Bashtool for running diagnostics, andWrite/Edittools for report generation, which could be exploited if the agent follows instructions found in logs. - Sanitization: There is no evidence of sanitization, filtering, or escaping of log content before it is processed by the model.
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to execute a wide range of diagnostic commands across the operating system, databases, and container orchestrators. - Evidence:
references/diagnostic-commands.mdcontains shell command templates forkubectl,psql,mysql,redis-cli, and standard Linux utilities likegrep,awk, andlsof. - [DATA_EXFILTRATION]: While the skill does not show signs of active exfiltration, it is explicitly instructed to access and examine sensitive system paths and configuration files which could lead to unauthorized data exposure.
- Evidence:
references/investigation-protocol.mdinstructs the agent to examine environment variables,.envfiles, and secret rotations as part of the deployment check process.
Audit Metadata