security-investigator-automation
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Downloads the security investigation framework and query library from a GitHub repository. This is a standard installation procedure for the described functionality.
- [DATA_EXFILTRATION]: Communicates with well-known threat intelligence services (IPInfo, AbuseIPDB, Shodan, and VPNapi) to enrich indicator data. These interactions are legitimate, authenticated via user-provided API keys, and essential for the skill's primary purpose of security analysis.
- [PROMPT_INJECTION]: The skill ingests and analyzes untrusted data from security logs (e.g., SigninLogs, DeviceProcessEvents) to generate summaries and findings. While this constitutes an indirect prompt injection surface, it is a necessary part of security monitoring, and the use of structured KQL queries helps mitigate risks associated with raw data processing.
Audit Metadata