incident-responder

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a purely informational security playbook. It does not contain any executable scripts, shell commands, or network-enabled logic.
  • [DATA_EXFILTRATION]: The skill mentions sensitive system paths (e.g., .ssh, .aws, .env) and credentials strictly for the purpose of guiding a human operator through an investigation and rotation process. It does not perform automated access to these resources.
  • [PERSISTENCE]: The documentation identifies common persistence locations (e.g., shell profiles, cron jobs) to assist in incident recovery. It does not attempt to establish persistence.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted incident descriptions from the user (Ingestion points: incident context; Boundary markers: absent; Capability inventory: file-read, file-write; Sanitization: absent). However, the lack of high-risk capabilities such as shell access or network communication effectively mitigates the risk of exploitation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:44 AM
Security Audit — agent-trust-hub — incident-responder