ir-playbook

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains safety directives instructing the agent to ignore any 'ignore previous instructions' commands found within the data it analyzes. While these are intended as security guardrails, they use phrases typical of prompt injection patterns.
  • [DATA_EXFILTRATION]: The skill is designed to handle sensitive incident data, including IP addresses, hashes, and business impact details. However, the executing environment is limited to read-only tools (Read, Grep, Glob) with no network access permissions defined in the frontmatter.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a high surface area for indirect prompt injection because its primary function is to ingest and analyze attacker-controlled content like logs and malware artifacts. It mitigates this by instructing the agent to treat such content strictly as data, although it lacks formal structural delimiters or automated sanitization for input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:06 AM
Security Audit — agent-trust-hub — ir-playbook