devops-incident-responder

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • COMMAND_EXECUTION (LOW): The skill includes instructions and templates for high-privilege commands (e.g., Docker cleanup, SQL session termination) which are necessary for incident response but present a risk if used maliciously. Evidence: docker system prune -f and pg_terminate_backend in SKILL.md.
  • PROMPT_INJECTION (LOW): The skill defines a workflow where the agent acts on external Prometheus alerts and webhooks, creating a surface for indirect prompt injection. 1. Ingestion points: Prometheus alerts and webhooks in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: SSH, Pod execution, and SQL administration. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:21 PM