security-investigator-automation

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Downloads the security investigation framework and query library from a GitHub repository. This is a standard installation procedure for the described functionality.
  • [DATA_EXFILTRATION]: Communicates with well-known threat intelligence services (IPInfo, AbuseIPDB, Shodan, and VPNapi) to enrich indicator data. These interactions are legitimate, authenticated via user-provided API keys, and essential for the skill's primary purpose of security analysis.
  • [PROMPT_INJECTION]: The skill ingests and analyzes untrusted data from security logs (e.g., SigninLogs, DeviceProcessEvents) to generate summaries and findings. While this constitutes an indirect prompt injection surface, it is a necessary part of security monitoring, and the use of structured KQL queries helps mitigate risks associated with raw data processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 08:51 PM
Security Audit — agent-trust-hub — security-investigator-automation