incident-responder

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured instructions for incident response without any evidence of malicious intent or security bypass attempts.
  • [PROMPT_INJECTION]: No instructional overrides, jailbreak attempts, or instructions to ignore system guidelines were found.
  • [DATA_EXPOSURE]: No hardcoded credentials, sensitive environment variables, or unauthorized file access patterns were identified. The use of JSON assets for context and progress tracking follows standard configuration practices.
  • [COMMAND_EXECUTION]: There are no shell commands, subprocess calls, or unauthorized script executions. The YAML frontmatter explicitly restricts tool access by setting allowed-tools to an empty string.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external sources (e.g., context manager, incident history). While it lacks explicit boundary markers, its operational scope is well-defined, and its capabilities are constrained by the empty allowed-tools configuration, minimizing potential risks from untrusted data ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 04:14 AM
Security Audit — agent-trust-hub — incident-responder