security-incident-response

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Upon activation, the skill instructs the AI agent to automatically verify the presence of recommended companion skills by executing a directory listing (ls) command across several hidden directories in the user's home and current directory (~/.claude/skills/, ~/.agent/skills/, etc.).
  • [EXTERNAL_DOWNLOADS]: Depending on the results of the local skill discovery check, the agent is directed to offer the installation of missing modules using the npx command, which retrieves packages from the vendor's repository.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and analyze external data such as incident logs, forensic artifacts, and threat indicators. Ingestion points: User-provided incident reports, log files, and TTP descriptions processed according to the NIST IR framework. Boundary markers: Absent; the instructions lack explicit delimiters or specific warnings to the agent to disregard potential instructions embedded within the analyzed evidence. Capability inventory: The agent can perform shell-based discovery operations and is authorized to provide high-privilege command-line recommendations to the user for system isolation and remediation. Sanitization: There are no defined input validation or sanitization routines for the data processed during incident analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:05 PM
Security Audit — agent-trust-hub — security-incident-response