incident-retrospective

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from external sources to draft retrospectives, creating an attack surface for indirect prompt injection.
  • Ingestion points: Slack incident channel messages and Linear follow-up tickets (SKILL.md).
  • Boundary markers: The setup instructions do not define specific delimiters or instructions to ignore potential commands embedded within the retrieved messages or tickets.
  • Capability inventory: The skill utilizes Slack, Linear, and Notion MCP tools and performs authenticated network requests to the automation backend.
  • Sanitization: The instructions lack explicit steps for sanitizing or filtering external content before it is interpolated into the prompt preset.
  • [COMMAND_EXECUTION]: The skill uses a shell command to register the automation prompt with the platform's backend service.
  • Evidence: curl -s -X POST "${OPENHANDS_HOST}/api/automation/v1/preset/prompt" in SKILL.md.
  • Context: The command uses environment variables provided by the platform (OPENHANDS_HOST and OPENHANDS_AUTOMATION_API_KEY) to communicate with the vendor's own infrastructure, which is standard functionality for this author.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 12:07 PM
Security Audit — agent-trust-hub — incident-retrospective