skills/jeremylongshore/claude-code-plugins-plus-skills/juicebox-incident-runbook/Gen Agent Trust Hub
juicebox-incident-runbook
Pass
Audited by Gen Agent Trust Hub on Mar 24, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
kubectlandcurlto perform system diagnostics and incident mitigation, such as restarting deployments and checking health status. These operations are restricted to the relevant application context. - [DATA_EXFILTRATION]: Accesses the
JUICEBOX_API_KEYenvironment variable to authenticate requests to the official service domain (api.juicebox.ai). This follows standard operational practices for secret management. - [SAFE]: Evaluation of the indirect prompt injection surface identifies that the skill ingests data from logs and status APIs to function. No malicious behavior was detected.
- Ingestion points:
kubectl logsandcurlstatus endpoints (references/implementation-guide.md). - Boundary markers: Absent.
- Capability inventory:
kubectl set envandkubectl rollout restart(references/implementation-guide.md). - Sanitization: Absent.
Audit Metadata