containment
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to process untrusted incident data including attacker-controlled indicators such as C2 strings and malicious command sequences, which presents a surface for indirect prompt injection. 1. Ingestion points: Section 8 (Prompt Injection Safety Notice) explicitly mentions processing attacker-sourced content. 2. Boundary markers: While the skill includes a textual 'Safety Notice' to the agent, it lacks structural delimiters (e.g., XML tags or clear separators) to prevent the agent from following instructions embedded in the analyzed data. 3. Capability inventory: The skill is restricted to low-privilege tools including Read, Grep, and Glob. 4. Sanitization: There is no evidence of programmatic sanitization or filtering of the external content before it is processed by the agent.
Audit Metadata