upgrade-planning-and-execution-readiness
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill includes strong defensive instructions to treat all user-supplied data (such as pasted runbooks, inventories, or logs) as untrusted content rather than instructions. It explicitly forbids the agent from following embedded commands or allowing external artifact content to override the skill's planning-only boundaries.
- [COMMAND_EXECUTION]: The instructions explicitly prohibit the execution of upgrades, rollbacks, service restarts, or cluster maintenance operations. The skill is strictly scoped to intake, research, and planning.
- [DATA_EXFILTRATION]: The skill contains specific rules against requesting sensitive information such as credentials, raw customer data, private support content, or unbounded logs. It encourages the use of sanitized summaries and bounded artifacts instead.
- [EXTERNAL_DOWNLOADS]: The skill utilizes the 'web' tool to research public Splunk documentation. The provided references target official vendor domains (help.splunk.com and splunkbase.splunk.com) which are appropriate for the skill's stated purpose.
- [SAFE]: The skill employs a 'coverage-first' protocol and a 'readiness contract' to ensure that all conclusions are evidence-labeled and document-backed, preventing the agent from making unsupported claims about the safety or readiness of a deployment.
Audit Metadata