devops-incident-responder
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- COMMAND_EXECUTION (LOW): The skill includes instructions and templates for high-privilege commands (e.g., Docker cleanup, SQL session termination) which are necessary for incident response but present a risk if used maliciously. Evidence:
docker system prune -fandpg_terminate_backendinSKILL.md. - PROMPT_INJECTION (LOW): The skill defines a workflow where the agent acts on external Prometheus alerts and webhooks, creating a surface for indirect prompt injection. 1. Ingestion points: Prometheus alerts and webhooks in
SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: SSH, Pod execution, and SQL administration. 4. Sanitization: Absent.
Audit Metadata