incident-retrospective
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from external sources to draft retrospectives, creating an attack surface for indirect prompt injection.
- Ingestion points: Slack incident channel messages and Linear follow-up tickets (SKILL.md).
- Boundary markers: The setup instructions do not define specific delimiters or instructions to ignore potential commands embedded within the retrieved messages or tickets.
- Capability inventory: The skill utilizes Slack, Linear, and Notion MCP tools and performs authenticated network requests to the automation backend.
- Sanitization: The instructions lack explicit steps for sanitizing or filtering external content before it is interpolated into the prompt preset.
- [COMMAND_EXECUTION]: The skill uses a shell command to register the automation prompt with the platform's backend service.
- Evidence:
curl -s -X POST "${OPENHANDS_HOST}/api/automation/v1/preset/prompt"inSKILL.md. - Context: The command uses environment variables provided by the platform (
OPENHANDS_HOSTandOPENHANDS_AUTOMATION_API_KEY) to communicate with the vendor's own infrastructure, which is standard functionality for this author.
Audit Metadata