incident-runbook-templates

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill templates include commands for high-privilege administrative tools such as kubectl and psql. These tools are used to perform actions like rolling back deployments (kubectl rollout undo), scaling services, and terminating database backends. While these are core to the skill's purpose, they represent a significant capability that could be misused if automated without oversight.\n- [INDIRECT_PROMPT_INJECTION]: The runbook patterns involve ingesting untrusted data from external sources, which creates a potential surface for indirect prompt injection.\n
  • Ingestion points: Data is ingested from service logs (kubectl logs) and external status/metric endpoints (curl to Prometheus and Stripe) as detailed in references/details.md.\n
  • Boundary markers: No specific delimiters or instructions are provided to help the agent distinguish between data and instructions within the logs.\n
  • Capability inventory: The templates grant the agent capabilities to modify system state, including scaling deployments, changing environment variables, and terminating database queries.\n
  • Sanitization: There is no documentation or implementation of sanitization for the log data or external responses before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:58 PM
Security Audit — agent-trust-hub — incident-runbook-templates