incident-runbook-templates

Warn

Audited by Snyk on Apr 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The SKILL.md runbook explicitly instructs checking and curling public third-party endpoints (e.g., https://sentry.io/payments, https://api.stripe.com/v1/health, status.stripe.com) as part of the incident workflow, so untrusted external content could be read and influence mitigation/next-action decisions.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.90). The runbook contains many explicit, privileged operational commands (kubectl rollout/scale/apply, psql pg_terminate_backend/VACUUM FULL, DB rollbacks, creating NetworkPolicy, writing to .claude/context/memory files, etc.) that would modify production/host state if executed by an agent with credentials, so it encourages changing the machine/cluster state.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 10, 2026, 10:51 PM
Issues
2