siem-rules

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely educational and instructional, providing templates for KQL (Microsoft Sentinel) and SPL (Splunk) queries. It does not possess capabilities for network access, file modification, or command execution.
  • [PROMPT_INJECTION]: While the skill contains keywords associated with prompt injection (e.g., 'ignore previous instructions'), these are utilized within a defensive 'Safety Notice' section. This section explicitly directs the agent to treat directives found within user-provided log samples or query drafts as data rather than commands, which is a recommended security practice to mitigate indirect prompt injection.
  • [SAFE]: The skill uses a restricted set of read-only tools and follows the principle of least privilege, focusing entirely on producing production-ready query text for human review.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 01:36 PM
Security Audit — agent-trust-hub — siem-rules