triage
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill acts as a procedural incident coordinator and does not implement high-risk behaviors such as direct command execution, network exfiltration, or obfuscation. It follows a strict delegation model, handing off implementation tasks to specialized agents (e.g., Builder, Gear, Sentinel) while mandating human approval for all remediation actions like rollbacks or scale changes.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data (monitoring alerts, user reports) and incorporates specific defense mechanisms to prevent and respond to indirect prompt injection. Evidence chain:
- Ingestion points: Monitors alerts and user reports defined in
SKILL.mdandreference/response-workflow.md. - Boundary markers: Uses confidence thresholds (P3/P5 authoring) and requires an explicit 'pause' action for low-confidence signals instead of autonomous continuation.
- Capability inventory: Coordinates critical operations such as rollbacks (
Gear) and security incident analysis (Sentinel) which are gated by human Incident Commander (IC) sign-offs. - Sanitization: Includes a dedicated 'Agent-Origin Incident' runbook (
reference/response-workflow.md§ A3) that provides specific containment and recovery instructions for when prompt injections reach external tools, ensuring destination and data-class validation.
Audit Metadata