responding-to-incidents

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use sudo and administrative privileges for essential forensic tasks such as memory dumping (avml, DumpIt), raw disk imaging (dd, ewfacquire), and mounting evidence filesystems. These capabilities are necessary for the skill's primary function and are aligned with standard forensic practices.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it involves the analysis of untrusted data sources (system logs, memory strings, and disk artifacts).
  • Ingestion points: Forensic images, memory captures, and various system/cloud logs (SKILL.md).
  • Boundary markers: Absent. The instructions do not explicitly mandate delimiters or specific instructions to disregard potentially malicious commands embedded within forensic artifacts.
  • Capability inventory: Significant capabilities including high-privilege shell command execution (sudo), file system modification, and cloud environment management via CLI tools.
  • Sanitization: Absent. There are no instructions for sanitizing or escaping content retrieved from forensic artifacts before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:46 PM
Security Audit — agent-trust-hub — responding-to-incidents